Who can use this?
- All Gallabox users can enable 2FA on their own account.
- Only Admins can enforce 2FA for all team members.
- Roles: Owners and Admins (for team-wide enforcement)
Why Enable 2FA?
Without 2FA, your account is protected by only one factor — your password. If someone guesses or steals your password, they have full access to your Gallabox account, including:- All customer conversation data
- All connected channels (WhatsApp, Instagram, Web Chat)
- All integrations (Shopify, HubSpot, payment data)
- All bot flows and automation settings
Supported 2FA Methods
Enabling 2FA on Your Account
Go to Two-Factor Authentication
Choose a method
Complete verification
- For Email Authentication, enter the verification code sent to your account email address.
- For TOTP Authentication, scan the QR code with your authenticator app and enter the code shown in the app.
Save your recovery codes
Recovery Codes
Recovery codes are one-time use codes that let you log in if you lose access to your authenticator app. Gallabox shows your recovery codes when you set up TOTP — save them at that point; they aren’t shown again. Important:- Each code can only be used once
- Store them securely — in a password manager, encrypted document, or safe location
- Never share recovery codes with anyone
Logging in with 2FA
After enabling 2FA, every time you log in:Enter your login details
Enter the 2FA code
Get the verification code
- For Email Authentication, open the verification email and enter the code.
- For TOTP Authentication, open your authenticator app, find Gallabox, and enter the current code.
Verify
Enforcing 2FA for Your Team
As an Admin, you can require all team members to enable 2FA:Open the Users, Teams and Roles settings
Enable the team requirement
Confirm the action
Enforcing 2FA for an individual member
You can also enforce 2FA for a single team member: open the three-dot menu on that user in Settings → Workspace → Users, Teams and Roles and choose the enforce option. Once enabled, the Owner or Admin can reset that user’s 2FA. After a reset, the user picks their preferred 2FA type at their next login.If You Lose Your 2FA Device
Method 1: Use a recovery code
Open the recovery code option
Enter a saved code
Set up 2FA again
Method 2: Contact support to reset 2FA
If you’ve lost both your device and recovery codes:Contact support
Wait for the reset
Enable 2FA again
Managing 2FA Settings
Resetting a team member’s 2FA
An Owner or Admin can reset a user’s 2FA:Open the user's menu
Reset 2FA
The user re-enrolls
If your recovery codes are unavailable
Recovery codes are generated and displayed during TOTP setup. If the saved codes are no longer available, ask an Owner or Admin to reset 2FA and complete TOTP setup again.Disabling 2FA
There is no direct option to disable 2FA from your account. If you need to change your 2FA setup, ask an Owner or Admin to reset your 2FA (via the three-dot menu on your user in Settings → Workspace → Users, Teams and Roles) — you’ll then pick your preferred 2FA type at your next login.FAQs
Does Gallabox support hardware security keys (YubiKey)?
Does Gallabox support hardware security keys (YubiKey)?
Will 2FA affect API access or integrations?
Will 2FA affect API access or integrations?
What happens if my team member refuses to enable 2FA?
What happens if my team member refuses to enable 2FA?
Can I use the same authenticator app for Gallabox and my other accounts?
Can I use the same authenticator app for Gallabox and my other accounts?