What is two-factor authentication?
XBert takes security seriously, so as well as your password, you need a second check when you log in. That second check is a 6-digit code from an authenticator app on your phone. The code changes every 30 seconds, so even if someone knew your password, they could not get into your XBert account without your phone.
Common authenticator apps include Google Authenticator, Microsoft Authenticator and Authy by Twilio.
Any of them will work.
You set this up the first time on your second login to XBert. It is tied to the particular phone you set it up on.
Why a new phone needs new setup
Your authenticator app stores a secret that was created when you first set up 2FA. That secret lives on the phone, not in your XBert account. When you move to a new phone, the new phone does not have it, so the codes it generates will not be accepted.
Some authenticator apps have a transfer or backup feature that moves your accounts to a new phone. If yours does and you have already used it successfully, you may find XBert is already there and working.
If not, follow the steps below.
Step 1: Ask us to reset your 2FA
There is no way to reset 2FA yourself from inside XBert, so the first step is to ask our support team to do it for you.
Start a chat with us using the chat bubble in XBert, or email support@xbert.io, and let us know you have a new phone and need your 2FA reset. We will confirm once it is done.
Until the reset is done, the steps below will not work, so please wait for our confirmation.
Step 2: Log in to XBert
Once we have confirmed the reset:
Close any browser tabs you have XBert open in.
Open a new tab and go to app.xbert.io.
Log in with your usual email address and password.
Because your 2FA has been reset, XBert will now take you through setting it up again, and a QR code will appear on your screen. A QR code is the square black and white pattern that your phone's camera can read.
Remember to delete any previous entries from XBert in your authenticator app. the old setup and the codes from it will not work once reset. You will have to use your new setup
Step 3: Add XBert to your authenticator app
On your new phone:
Open your authenticator app.
Choose the option to add a new account. In most apps this is a plus (+) button.
Choose the option to scan a QR code.
Point your phone's camera at the QR code on your computer screen.
Your app will add an entry for XBert and start showing a 6-digit code that refreshes every 30 seconds.
Step 4: Enter the code
Type the 6-digit code from your authenticator app into XBert and confirm. That completes the setup, and you will be taken into XBert as normal.
From now on, whenever you log in, you will be asked for a fresh 6-digit code from this app.
Step 5: Tidy up your old phone
If you still have your old phone and the XBert entry is still in its authenticator app, you can delete that entry. It will no longer generate valid codes.
Troubleshooting
The setup screen did not appear when I logged in. Close your browser completely, reopen it, go to app.xbert.io and log in again. It is worth checking with us that your reset has actually been completed.
My camera will not scan the code. Make sure your screen brightness is up and hold the phone steady about 20cm from the screen. If the setup screen offers an option to enter a code by hand instead of scanning, you can use that and type the code into your authenticator app manually.
My code is being rejected. Codes expire after about 30 seconds, so if the code changes while you are typing, wait for a fresh one and enter that. If codes are still rejected, check that the date and time on your phone are set to update automatically, as a phone clock that has drifted will produce codes that do not match.
I have lost my phone and cannot log in. Contact us and we will reset your 2FA so you can set it up again on your replacement device.
Still stuck?
Start a chat with us from the chat bubble in XBert, or email support@xbert.io, and we will help you get back in.
