Account & Security
Setting up two-factor authentication
How to enable 2FA on your Dapplon account using an authenticator app, and how to recover access if you lose your device.
What is two-factor authentication?
Two-factor authentication (2FA) adds a second verification step to your login. Even if someone knows your password, they cannot log in without the 6-digit one-time code from your authenticator app. This protects your account from phishing and credential-stuffing attacks.
Dapplon uses Time-based One-Time Passwords (TOTP), compatible with Google Authenticator, Microsoft Authenticator, and Authy.
Note
SuperAdmin accounts (nu.dapplon.com) have mandatory 2FA. For all other panels, 2FA is optional but strongly recommended for anyone with payroll or employee data access.
Setting up 2FA — first time
- Log in to your Dapplon panel
- Click your avatar in the top-right corner
- Go to Account Settings > Security
- Click Enable Two-Factor Authentication
- Open Google Authenticator (or any TOTP app) on your phone
- Tap the + button in the app and choose Scan QR Code
- Point your phone camera at the QR code shown on the Dapplon screen
- The app adds a new entry named "Dapplon" and shows a 6-digit code
- Enter that 6-digit code in the confirmation field on the Dapplon screen
- Click Verify and Enable
- Dapplon shows you 8 backup recovery codes — save these somewhere safe (printed or in a password manager)
Logging in with 2FA enabled
- Enter your email and password as usual
- Click Sign In
- You are taken to a screen asking for your 6-digit code
- Open your authenticator app and find the Dapplon entry
- Enter the current 6-digit code — it refreshes every 30 seconds
- Click Verify
If you lose access to your authenticator app
If your phone is lost or the authenticator app is deleted:
- Use one of your saved backup recovery codes on the 2FA verification screen
- Once logged in, go to Account Settings > Security and disable 2FA
- Re-enable it with your new device
If you have no backup codes either, contact your Dapplon admin or email [email protected]. An admin can disable 2FA from the SuperAdmin panel after identity verification.
In this section
- Logging in to Dapplon
- Resetting your password
- Understanding roles and permissions
Was this page helpful?