Two-Factor Authentication
Add a second step to your sign-in so even a leaked password can’t get into your account on its own.
Last updated 2026-05-22
Why it matters here
The Birmingham Neighborhood Platform holds civic records — election outcomes, meeting minutes, foundation finances — that need to stay trustworthy. A leaked or guessed password is the most common way accounts get taken over. Two-factor authentication blocks that pathway by requiring a second proof of identity beyond your password.
NA admins, foundation board members, and city auditors are encouraged to enable two-factor immediately. The platform may also require it for those roles in the future per the Citizen Participation Plan and CDBG compliance reviews.
How it works
Visit Settings → Two-factor authentication and click "Enroll." The platform shows you a QR code and a setup key. Open an authenticator app on your phone (Google Authenticator, Authy, 1Password, or any TOTP-compatible app) and scan the code — that links your phone to your account.
From then on, every sign-in asks for both your password and a six-digit code from the authenticator app. The codes refresh every 30 seconds, so they expire quickly even if someone catches a glimpse.
The platform also gives you 10 single-use recovery codes during enrollment. Save them somewhere safe (a password manager, a printed copy in a drawer). If you lose your phone, those codes get you back in.
If you lose your phone
Use one of your saved recovery codes to sign in. Each code works once and then is permanently spent — the platform tracks remaining count for you in Settings.
If you’re out of recovery codes, contact a platform administrator. They can reset your enrollment so you can set up two-factor again on a new device. This path is intentionally manual because resetting two-factor is the most powerful attack vector on the system — humans look at it.