Authenticator apps and passkeys
The emailed code is the second factor everyone starts with. An authenticator app or a passkey replaces it: nothing to wait for in your inbox, nothing to retype, and no dependency on mail being delivered. Both live under Settings → Sign-in security, both are yours alone, and an admin can reset them but can never see them.
Set up an authenticator app
Any TOTP app works: Microsoft Authenticator, Google Authenticator, 1Password, Bitwarden, Authy. If your company already standardises on one, use that one.
- 1Open Settings → Sign-in securityIt lists the factors on your account and says so if your workspace requires an app or a passkey.
- 2Choose Add authenticator appCurrent shows a QR code, and the same secret as text for a desktop password manager that can't scan a screen.
- 3Scan it, then type the 6 digitsYour app starts generating a code every 30 seconds. Enter the current one to finish. The factor isn't active until that code verifies, so a setup you abandon half-way leaves you exactly where you were. It is listed as Authenticator app; a second one becomes Authenticator app 2.
Set up a passkey
A passkey is a key your device holds and unlocks with Face ID, Touch ID, Windows Hello, or a hardware security key. There is nothing to type and nothing that can be read off your screen and reused.
- 1Choose Add passkeySame page: Settings → Sign-in security.
- 2Confirm with your deviceYour browser asks for the fingerprint, face, PIN or key you already use. Where the passkey is saved — the device itself, iCloud Keychain, a password manager, a USB key — is your browser's question, not Current's.
- 3Add a second factor as wellA passkey on one laptop is a passkey you lose with the laptop. Add your phone too, or keep an authenticator app beside it, so a single dead device isn't a call to your admin.
Signing in once you have one
From then on Current stops offering you the emailed code. You sign in with your password, then your app or your passkey, and the browser is trusted afterwards in exactly the same way and for exactly the same window. The code path is closed for you rather than hidden: a code requested some other way is refused.
Removing a factor
Settings → Sign-in security, then Remove on the factor. Current asks you to use that factor first — a code from the app you're removing, a touch of the passkey — so somebody sitting at your unlocked laptop can't quietly strip it. Remove your last app or passkey and you go back to the emailed code. If your workspace requires an app, Current refuses to remove your last one until you have added another.
Lost the phone, lost the key
- 1Ask a workspace admin for a resetWorkspace → Users & roles, the ⋯ menu on your row, Reset second factor. It clears the factors on your account and un-trusts every browser you had, so you start the second step over; it never reveals a factor and never moves one to another device.
- 2Sign in againOn the default setting you're back to the emailed code and there is nothing else to do. If your workspace requires an authenticator app or a passkey, your next sign-in asks you to enrol a new one before you reach the workspace.
- 3No admin availableITPartners+ support can run the same reset. Use the contact form in the Help Center; we confirm who you are with your workspace before anything changes.
What your workspace can require
A Tenant Admin can raise the floor from Email code to "Authenticator app or passkey" in the Sign-in panel at Workspace → Users & roles, with the Require an app or passkey button. The same panel's roster shows who has an app or a passkey already and who is still on the emailed code. It is a one-way change: a workspace that requires an app can't go back to email codes. After it, anyone without a factor is asked to enrol at their next sign-in. The same panel shortens how long a browser stays trusted, from 30 days to 14 or 7.
