Two-factor authentication (2FA)

Tutorial: How to set up two-factor authentication in CashCtrl.

Content 

  1. Enable two-factor authentication
  2. Download App and scan QR code
  3. Log in again, done
  4. Good to know / Troubleshooting
Screenshot der Zwei-Faktor-Authentisierung

Why two-factor authentication?

To protect your own account, it makes sense not to rely on just one password. Two-factor authentication still offers a fast and uncomplicated login, but with a massively higher security factor. Here, access is verified with a second element, a token. The token is generated in an independent smartphone app such as Google Authenticator or Authy, for example.

1. Enable two-factor authentication

Open the profile edit dialog via Settings User profile or by clicking on the user icon in the meta menu. Here check the box for Enable two-factor authentication (2FA).

A popup with a QR code opens.

Screenshot of the user profile settings for setting up the 2FA

2. Download app and scan QR code

Download an authentication app to the smartphone - we recommend here without obligation:

Download the app from the Google Play Store or the App Store and open it. Scan the QR code displayed in CashCtrl from the app via the icon (add account). If you prefer a more complex process, you can enter the code below the QR code manually into the app.

Complete the process by clicking on Save.

Screenshot of the two-factor authentication setup with QR code

3. Log in again, done

Now log out and log in again. After successfully entering the password, CashCtrl will now also request the token from the app.

Enter it and you're done. That's it. You have greatly increased the security of your account.

Screenshot of the login screen of CashCtrl

4. Good to know / Troubleshooting

  • Smartphone change/loss: We recommend noting the code below the QR code so that if the smartphone is changed or lost, the 2FA can be set up again on another device with an authentication app.
  • Invalid token: If the login does not work because the token is invalid, the reason could be that the system time of the smartphone is not set to "automatic time".
Screenshot of the backup code to set up two-factor authentication again on another device