Securing Your Account

Enable two-factor authentication, manage recovery codes, and keep your CargoLint account safe.

Two-factor authentication (2FA) adds an extra security layer to your CargoLint account. After you enter your password, you’ll be asked to provide a second form of verification using an authenticator app.

Why enable 2FA?

Even if someone learns your password, they can’t access your account without your authenticator. This protects your documents, team settings, billing, and any integrations you’ve configured.

We strongly recommend enabling 2FA, especially if you have admin or owner access.

Setting up 2FA

To enable two-factor authentication:

  1. Go to Settings (gear icon in the top right).
  2. Click Security.
  3. Click Enable Two-Factor Authentication.

A QR code and backup code will appear on the screen. Save your backup codes immediately—you’ll need them if you lose access to your authenticator app.

Scanning the QR code

  1. Open your authenticator app (see “Supported apps” below).
  2. Tap the option to add or scan a new account.
  3. Point your phone at the QR code on the screen.
  4. Your authenticator app will scan it and show “CargoLint” with a 6-digit code.

Do not close this screen yet. You’ll need to verify the code in the next step.

Verifying your authenticator

  1. Copy the 6-digit code from your authenticator app.
  2. Paste it into the “Enter verification code” field on the CargoLint screen.
  3. Click Verify.

If the code is correct, you’ll see a confirmation message and 2FA will be enabled immediately.

Saving your recovery codes

When 2FA is enabled, CargoLint generates 8 recovery codes. These are single-use codes that work like a password if you lose access to your authenticator.

To save your recovery codes:

  1. After 2FA is verified, you’ll see a list of 8 codes.
  2. Screenshot or copy them to a secure location (like your password manager).
  3. Store them somewhere safe—not on your computer or phone.
  4. Click I’ve Saved My Recovery Codes to continue.

You can download your recovery codes as a PDF for printing.

Supported authenticator apps

CargoLint works with any TOTP-based authenticator, including:

  • Google Authenticator (iOS, Android)
  • Microsoft Authenticator (iOS, Android)
  • Authy (iOS, Android, desktop)
  • 1Password (iOS, Android, desktop, Mac, Windows)
  • Bitwarden (iOS, Android, desktop, Mac, Windows, browser extension)

Each of these apps generates a 6-digit code that changes every 30 seconds. The codes are not transmitted over the internet—they’re generated locally on your device.

If you don’t have an authenticator app, download one from your phone’s app store (search for “authenticator” or “two-factor”).

Using your authenticator during login

Once 2FA is enabled:

  1. Go to the CargoLint login page.
  2. Enter your email and password.
  3. You’ll see a “Two-Factor Code” prompt.
  4. Open your authenticator app and find the 6-digit code next to “CargoLint”.
  5. Enter the code and click Sign In.

The code is valid for 30 seconds. If it expires before you submit it, open your app again—a new code will have generated.

Using a recovery code

If you lose access to your authenticator, you can use a recovery code to sign in:

  1. Go to the CargoLint login page.
  2. Enter your email and password.
  3. On the “Two-Factor Code” prompt, click Use a recovery code (usually a small link).
  4. Enter one of your 8 backup codes.
  5. Click Sign In.

Important: Recovery codes are single-use. Once you use one, it’s gone and you’ll need to use another one next time.

After you use a recovery code, we recommend you set up a new authenticator as soon as possible to regenerate your code set.

Disabling 2FA

You can disable two-factor authentication if needed:

  1. Go to Settings > Security.
  2. Click Disable Two-Factor Authentication.
  3. Enter your password to confirm.
  4. Your 2FA will be disabled immediately.

Without 2FA, your account relies only on your password for security. We recommend re-enabling it as soon as you’ve resolved whatever issue required disabling it.

Losing access to your authenticator

If you lose your phone or reset your device and can’t access your authenticator:

You have a recovery code: Use it to sign in (see “Using a recovery code” above).

You don’t have your recovery codes: Contact our support team at support@cargolint.com with proof of ownership (e.g., the email address associated with your account). We can help you regain access, but there may be a security verification process.

To prevent this situation: Save your recovery codes somewhere safe, not just on your phone.

Password management tips

While 2FA protects against unauthorized access, a strong password is still your first line of defense.

  • Use a unique password: Don’t reuse passwords across websites. If another site is compromised, your CargoLint account should remain safe.
  • Use a password manager: Tools like 1Password, Bitwarden, or Dashlane securely generate and store strong passwords.
  • Enable in your password manager: Some password managers can store TOTP codes as well, adding extra convenience.
  • Change your password regularly: Update your CargoLint password every few months, especially if you suspect any compromise.

To change your password:

  1. Go to Settings > Security.
  2. Click Change Password.
  3. Enter your current password.
  4. Enter your new password twice.
  5. Click Update Password.