Two-Factor Authentication Is Optional on Cantrip. Turn It On Anyway.

Two-Factor Authentication Is Optional on Cantrip. Turn It On Anyway.

Turning on two-factor authentication for your Cantrip account takes about ninety seconds. Scan a QR code with an authenticator app (Google Authenticator, Authy, 1Password, whatever you already use), type in the six-digit code it shows you, and you're done. No support ticket, no waiting period. It's live the moment that first code checks out.

Here's the part most people don't expect: logging into the Cantrip portal doesn't use a password at all. You get a code emailed to you, or you sign in with Google. Two-factor sits on top of either one, as a second gate right after. Connect through the MCP server or the API instead (Claude, ChatGPT, a script you wrote), and that path does use a password, with your authenticator code layered on there too.

You'll find the toggle under Account, in your user settings. Not under a "Security" tab. There isn't one. Once it's turned on, every login from then on, magic code or Google, stops at a six-digit prompt before it lets you through.

Don't want to type a code every single time? Check "trust this device" the first time you're asked, and that browser skips two-factor for thirty days. Turn two-factor off entirely and every trusted device gets forgotten at the same moment, on purpose, so an old "trusted" laptop can't quietly outlive the protection it was supposed to be part of.

Guess wrong five times, setup or login, and Cantrip locks that attempt out for a while. The lockout is tallied per account, not per IP address, so spreading guesses across five different networks doesn't buy five more tries. It just gets you locked out faster.

Now the honest gap. There's no recovery code, no "I lost my phone" button anywhere in the product. Lose the one device your authenticator lives on and there's no self-serve way back into your account. The fix costs nothing extra: most authenticator apps let you add the same account to a second phone or tablet right when you first set it up, and Cantrip doesn't cap you at one verified device either. Do that on day one and you've got a backup sitting in a drawer instead of a support ticket later.

Nobody's forced into any of this. Two-factor is entirely opt-in, decided per person, not per team. Invite five people to your Cantrip team and every one of them chooses for themselves whether to turn it on. Cantrip nudges you about it from the dashboard once you've got a live site and an active plan, a small "secure your account" banner, nothing that blocks your work. It's easy to dismiss and easy to forget. Don't. A compromised email account is the actual way most people lose access to things like this, and two-factor is the cheapest insurance against it you'll set up all year.