Skip to main content

Set up two-step authentication (Authenticator app, SMS, or Spendesk mobile app)

How to set up and manage your two-step authentication method on Spendesk.

Set up two-step authentication (Authenticator app, SMS, or Spendesk mobile app)

Two-step authentication (also called Strong Customer Authentication, or SCA) adds a second verification step to confirm your identity for sensitive actions — such as logging in, revealing a card PIN, or approving a wire transfer. This article explains how to set up and manage your authentication method.

For: All Spendesk users.

Before you start

  • No specific role is required. Every Spendesk user must set up at least one two-step authentication method.

  • Spendesk supports three methods: Authenticator app (TOTP), Spendesk mobile app, and Text message (SMS).

  • We recommend setting up more than one method so you always have a backup if one becomes unavailable.

  • To use SMS, you must first add your mobile phone number to your profile.

  • To enroll in TOTP directly from your phone (without a web browser), you need the Spendesk iOS app. Android in-app enrollment is coming soon.

Set up your two-step authentication (web)

Step 1 — Open your profile

  1. Click your avatar in the bottom-left corner of Spendesk.

  2. Select "My Profile".

Step 2 — Add an authentication method

  1. Click the "Security" tab.

  2. Click "Add an authentication method" under Authentication methods.

Step 3 — Choose your method

Two methods are available from this screen: Authenticator app and Spendesk mobile app. You can also enable Text message (SMS) by adding your phone number in the Phone number section of your profile.

Option A — Authenticator app (TOTP)

The Authenticator app method uses the TOTP (Time-based One-Time Password) standard — a widely adopted security protocol that generates a new 6-digit code every 30 seconds. TOTP is available as of June 26, 2026.

  1. Select "Authenticator app".

  2. Download a TOTP-compatible app on your mobile device or computer: Google Authenticator (iOS / Android), Microsoft Authenticator (mobile and desktop), or 1Password (mobile and desktop).

  3. Click "Show the QR code" in Spendesk.

  4. Scan the QR code with your authenticator app.

  5. Click "Continue".

  6. Enter the 6-digit code shown in your authenticator app to confirm setup.

At your next sensitive action (login, reveal PIN, wire transfer), select "Use an alternate authentication method" to use your authenticator app code.

💡 Tip: Store your authenticator app backup codes or link the app to a cloud account. This ensures you can restore access if you switch phones.

Option B — Authenticator app (TOTP) via Spendesk iOS app

You can now enroll in TOTP directly from the Spendesk iOS app, without using a web browser.

  1. Open the Spendesk iOS app.

  2. Follow the in-app prompts to set up TOTP authentication.

  3. Confirm enrollment when prompted.

💡 Note: Android support for in-app TOTP enrollment is coming soon. Android users should set up TOTP through the web app for now.

Option C — Spendesk mobile app (push notification)

  1. Select "Spendesk mobile app".

  2. Download the Spendesk mobile app on your phone.

  3. Follow the in-app steps to register your phone as a trusted authentication device.

When a sensitive action requires authentication, you will receive a push notification. Open the app and approve the action directly.

⚠️ Note: Only one device can be registered for mobile app authentication at a time. If you change phones, you will need to re-enroll.

Option D — Text message (SMS)

  1. Go to "My Profile" and add your mobile phone number in the Phone number section.

  2. Select the SMS method when prompted for two-step authentication.

⚠️ Security note: SMS is the least secure method and is vulnerable to SIM swap and SS7 attacks. Use it only as a backup when other methods are not available.

Where two-step authentication is required

Once set up, your authentication method is used to confirm the following actions:

Action

Required

Log in to the Spendesk web app

Yes

Reveal a physical card PIN

Yes

Reveal a virtual card PAN

Yes

Show or reset payment password (UK only)

Yes

Approve a wire transfer

Yes (Account Owners)

Access transaction data on the web app

Yes (every 90 days — AOs, Controllers, Admins)

👥 Roles: Only an Account Owner or Administrator can issue a recovery code to unblock a user who has lost access to their authentication method.

Security recommendations

  • Set up multiple methods so you can still access your account if one becomes unavailable.

  • Prefer TOTP or the Spendesk app over SMS — both are more secure and not vulnerable to SIM swap attacks.

  • Keep your authenticator app linked to a cloud account (Google, Microsoft) or back up your recovery codes so you can restore access if you change phones.

⚠️ Warning: If you lose access to all your authentication methods, you cannot log in or complete sensitive actions until an Account Owner or Administrator issues a recovery code.

Troubleshooting

Symptom: The user changed phones and their authenticator app codes no longer work.
Cause: The authenticator app was not linked to a cloud account, so codes did not sync to the new device (for example, Authy used in offline mode).
Resolution: Ask an Account Owner or Administrator to issue a recovery code, then re-enroll in Spendesk using a new QR code scan. If the app was linked to a cloud account (Google, Microsoft), reinstalling and signing in with the same account restores codes automatically.

Symptom: The user lost access to their authenticator app and cannot log in or complete a sensitive action.
Cause: The user's authentication method is no longer available on their device.
Resolution:

  1. Contact your Account Owner or Administrator to request a recovery code.

  2. On the "Choose a way to authenticate" screen, click "Lost access to your authentication method?"

  3. Enter the recovery code to restore access.

  4. Once logged in, set up a new authentication method immediately.

Symptom: The user is not receiving push notifications from the Spendesk app.
Cause: Notifications may be disabled, the app may be outdated, or a pending action was not detected.
Resolution:

  1. Check that notifications are enabled for the Spendesk app in your phone's settings.

  2. Open the app manually — if a pending action exists, the confirmation screen appears automatically.

  3. Make sure the app is updated to the latest version.

  4. If the issue persists, delete and reinstall the app.

FAQs

Can I use multiple authentication methods at the same time?
Yes. Spendesk supports having more than one method configured. We recommend it as a backup strategy.

Can I switch back to SMS if I set up TOTP?
Yes. You can add or remove authentication methods at any time from My Profile > Security.

Why can't I use SMS anymore after setting up the mobile app?
Once you enroll the Spendesk mobile app as your primary method, it becomes your default. You can still add SMS as a backup from your profile settings.

Is TOTP available for all users?
Yes. TOTP (Authenticator app) has been generally available since June 26, 2026, for all Spendesk users.

Related articles

Did this answer your question?