How to set up two-factor authentication
MagicPost two-factor authentication adds a 6-digit code to each login, on top of your password or of Google. You turn it on yourself in Settings, under the Security tab, with an authenticator app or with codes sent by email. Two-factor authentication is optional and exists on every MagicPost account, free or paid.
The two methods
Authenticator app. An app such as Google Authenticator, 1Password or Authy generates the MagicPost code on your phone. MagicPost presents this method as the most secure one.
Email code. MagicPost sends a code to the email address of your account each time you log in.
A MagicPost account uses one method at a time. An account set up with the authenticator app can still ask for a code by email, as a fallback, when the phone is not at hand.
How to turn on two-factor authentication in MagicPost
Open the profile menu at the bottom of the MagicPost sidebar and select Settings, then go to the Security tab. This link opens the tab directly: app.magicpost.in/settings?tab=security.
On the Two-factor authentication card, click Enable.
In the Enable two-factor authentication window, select Authenticator app or Email code, then click Continue.
With Authenticator app, scan the QR code with your app. If you cannot scan it, copy the key shown under "Can't scan it? Enter this key in the app:" and add it to the app by hand. With Email code, open the email MagicPost just sent you.
Type the 6-digit code in the code field of the window and click Enable.
MagicPost turns two-factor authentication on only after this first code is accepted. If you close the window before step 5, nothing changes on your account and you cannot lock yourself out. Once two-factor authentication is on, the card shows Active with the method in use, and MagicPost sends a confirmation email to your address.
What changes when you log in to MagicPost
After your password, or after Google, MagicPost shows a Two-step verification screen. Enter the code from your authenticator app, or the code MagicPost sent by email, and click Verify code. MagicPost asks for a code at each new login.
The MagicPost verification step stays open for a limited time and accepts a limited number of wrong codes. Past either limit, MagicPost shows "The verification has expired. Please log in again." or "Too many attempts. Please try again later.", and you start again from the login form. Back to login cancels the step.
With the email method, Resend code sends a new code. The button shows a countdown before you can use it again, and MagicPost limits how many codes it sends to one account per hour.
How to turn off two-factor authentication or switch method
Open Settings, then the Security tab.
On the Two-factor authentication card, click Disable.
Enter a code from your authenticator app, or click Get a code by email and enter the code you receive.
Click Disable.
MagicPost always asks for a valid code before it turns two-factor authentication off, and sends an email to your address when it is off. MagicPost has no button to switch method directly: turn two-factor authentication off, then turn it on again with the other method.
What two-factor authentication also protects
With two-factor authentication on, MagicPost asks for a Two-factor authentication code: before it changes the email address of your account or deletes the account. See how to change your email address and how to delete your account. A password reset does not turn two-factor authentication off: the code is still asked at the next login.
Two-factor authentication covers your own logins to the MagicPost app. Requests made with a MagicPost API key are not asked for a code: see how to create an API key.
MagicPost two-factor authentication does not apply when an organization admin opens the account of a member from the organization: the admin is not asked for the member's code. In that session, MagicPost refuses to change the email address of the member's account or to delete it.
FAQ
I lost my phone or my authenticator app. How do I log in to MagicPost?
On the Two-step verification screen, click Get a code by email. MagicPost sends a code to the email address of your account, and that code is accepted in place of the app code. Once logged in, turn two-factor authentication off and on again to link a new phone.
I lost access to both my authenticator app and my mailbox. What can I do?
Contact MagicPost support at support@magicpost.in. MagicPost has no backup codes, so only the support team can remove two-factor authentication from an account that is locked out. The account receives an email when this is done.
Does MagicPost ask for a code when I log in with Google?
Yes. Two-factor authentication applies to both ways of logging in to MagicPost. After Google confirms your identity, MagicPost shows the same Two-step verification screen.
Can I tell MagicPost to remember my device and skip the code?
No. MagicPost asks for a code at each new login and has no option to trust a device. You stay logged in on a browser until you log out or the session ends.
Why is the Two-factor authentication card missing from my Security tab?
MagicPost hides the card in a session opened on behalf of someone else, for example when an organization admin opens the account of a member. The admin opens that session without the member's code. Two-factor authentication can only be managed by the person logged in to their own MagicPost account.
Need help?
If you cannot log in to MagicPost, email support@magicpost.in. Once you are logged in, you can also reach out via the in-app chat.