Workspace 2FA
Last updated: October 6, 2026
Two-factor authentication (2FA) adds a one-time code from an authenticator app to your Workspace login and to sensitive Workspace actions. It protects access to the Workspace in Safe{Wallet}. It's separate from the onchain signing security of your Safe Accounts and never replaces it.
How it works
Second factor: A time-based one-time code (TOTP) from an authenticator app.
Email or Google login: You enter a code when you log in, and again for sensitive admin actions.
Wallet login (Sign-In With Ethereum): You enter a code for sensitive admin actions.
Changing authenticator: You can switch to a different authenticator app.
What 2FA covers
2FA protects your login to the Workspace and sensitive actions in it, such as managing members and roles.
It does not apply to signing. Signing a transaction always requires the Safe Account's signers and threshold, whether or not 2FA is on.
If you lose access to your authenticator
Losing access to your second factor, or to the Workspace, never affects funds, signing rights or access to any Safe Account. Each Safe Account stays fully usable on its own with its signers' keys.
Limitations
2FA doesn't protect, back up or recover private keys or recovery phrases.
It doesn't stop a transaction that has been approved by the required signers, and it doesn't protect against a compromised signer wallet.
It reduces the risk of unauthorised access but doesn't eliminate it. Phishing, malware or a compromised device can still get around it.