Skip to content

Two-Factor Authentication (2FA) ​

Two-factor authentication (2FA) adds a second identity verification step at login — in addition to your password, a one-time code generated by an app on your phone is required. Even if your password is compromised, your account remains protected.

Table of Contents ​

Why you should enable it ​

Your Sembot account may have access to Google Ads and Microsoft Advertising accounts, store revenue data, and campaign budgets. A compromised account puts you at risk of uncontrolled ad spend and customer data leaks.

2FA effectively blocks most attacks based on stolen passwords (phishing, credential stuffing). Enabling it is especially important if:

  • you have the role of project owner or administrator,
  • connected advertising accounts with an active budget have access to the account,
  • you log in from multiple devices or networks.

Setup via TOTP app (Google Authenticator, Authy) ​

Sembot supports the TOTP (Time-based One-Time Password) standard — the same one used by Google Authenticator, Authy, Microsoft Authenticator, and most password managers.

  1. Go to Account Settings → Security → Two-Factor Authentication.
  2. Click Enable 2FA.
  3. Open the TOTP app on your phone and scan the displayed QR code (or manually enter the text key shown below the code).
  4. Enter the 6-digit code generated by the app and click Confirm — Sembot will verify that the configuration is correct.
  5. Save your backup codes (see the section below) — without them, losing your phone may lock you out of your account.

From this point on, every login will require entering a code from the app after entering your password.

Tip: If you log in via SSO (Google, Microsoft), Sembot's 2FA is not required during login itself — your identity is verified by the SSO provider. It is still recommended to enable 2FA on the provider's side (e.g., in your Google account settings).

Backup codes — where to store them ​

During 2FA setup, Sembot generates 10 single-use backup codes. These are used to log in when you don't have access to the TOTP app (lost phone, deleted app, device replacement).

How to store them:

  • Save them in a password manager (e.g., 1Password, Bitwarden) — the most convenient option.
  • Print them and keep them in a secure offline location.
  • Save them in an encrypted file in the cloud.

What to avoid:

  • Do not store the codes only on the same phone as the TOTP app — losing the phone means losing both.
  • Do not save the codes in an unencrypted text file on your disk.

Each code can only be used once. After using all codes, return to the security settings and generate a new set.

Disabling 2FA ​

You can disable 2FA in Account Settings → Security → Two-Factor Authentication → Disable.

Sembot will ask you to confirm by entering your current TOTP code or one of your backup codes. If you don't have access to either, contact support — identity verification will then be done manually.

Note for administrators: If your organization requires 2FA for all project users, disabling 2FA by a user may be blocked by the security policy set at the project level.