Skip to main content

Two-Factor Authentication & Passkeys

How to set up authenticator app (TOTP) two-factor authentication and passkeys, and how to sign in with each.

Written by Derek Carr

BSCpro supports two ways to add a second layer of security to your account on top of your password: an authenticator app code (TOTP) and a passkey. You can set up one or both. This article walks through enabling each one and signing in once they're turned on.

Before you start: where these settings live

Both features are managed from your Profile page: click your avatar in the top right, choose your profile, and stay on the first tab, Profile. Two-Factor Authentication and Passkeys each have their own button next to Change Password.

Setting up two-factor authentication (authenticator app)

Two-factor authentication (2FA) uses a 6-digit code that refreshes every 30 seconds, generated by an app on your phone. Even if someone learns your password, they can't sign in without that code too.

  1. Install an authenticator app on your phone if you don't already have one (see the list below).

  2. On your Profile page, click Set Up 2FA.

  3. A window opens with a QR code and a manual entry key. Open your authenticator app and either scan the QR code, or choose "enter a setup key manually" and type in the key shown.

  4. Your authenticator app will start showing a 6-digit code for your BSCpro account. Type that code into the 6-digit code field and click Verify & Enable.

Recommended authenticator apps

Any standard TOTP authenticator app works. A few popular options:

Save your backup codes

As soon as 2FA is turned on, BSCpro shows you 10 backup codes. Each one can be used once, instead of your authenticator app, if you ever lose your phone. Save them somewhere safe right now — they're only ever shown this one time. A password manager or a printed copy in a safe place both work well. If you run out or lose them, you can generate a fresh set by disabling and re-enabling 2FA.

Setting up a passkey

A passkey lets you sign in using your device's fingerprint, face recognition, or screen lock (Face ID, Touch ID, Windows Hello, or a physical security key) instead of typing a password at all. It's built on the same technology banks and major tech companies use, and it can't be phished the way a password can.

  1. On your Profile page, click Enable Passkey (or Manage Passkeys if you already have one).

  2. Give this device a name, like "Work Laptop" or "iPhone," so you can recognize it later if you ever need to remove it.

  3. Click Add a Passkey, and follow your browser or device's prompt to confirm with your fingerprint, face, or screen lock.

You can register more than one passkey — for example, one for your laptop and one for your phone — and remove any of them later from the same window.

Note: passkeys require a modern browser and won't be available on very old browsers or devices.

Signing in with 2FA or a passkey

Signing in with your password + an authenticator code

  1. Go to the login page and enter your username/email and password as usual, then click Log in.

  2. If you have 2FA enabled, you'll be taken to a "Enter your verification code" screen. Open your authenticator app and type the current 6-digit code into the boxes.

  3. Click Verify to finish signing in.

Lost access to your authenticator app? Click "Having trouble? Use a backup code" on that same screen and enter one of the 10 backup codes you saved during setup instead.

Signing in with a passkey

  1. Go to the login page and click Sign in with a passkey — you don't need to type your username or password first.

  2. Confirm with your device's fingerprint, face recognition, or screen lock when prompted.

That's it — a passkey satisfies both your password and your 2FA code in one step, so there's nothing else to enter.

Turning 2FA or passkeys off

From the same Profile page, click Disable 2FA (you'll be asked to confirm with your current password) or open Manage Passkeys and click Remove next to any passkey you no longer want to use.

Did this answer your question?