Enable 2-Factor Authentication
Adding extra security to your WhatPulse account can be achieved using our 2-Factor Authentication (2FA) implementation. We use a Time-based One-Time Password (or TOTP) and Passkey methods, which means you can receive a code via an authenticator app or use a Passkey to prove that it's actually you that's trying to log in.
Passkeys
Passkeys allow you to log in securely without entering a password, using biometrics (like Touch ID/Face ID) or hardware security keys. For more information on how passkeys work, you can read Dashlane's guide on Passkeys.
If you wish to use a physical hardware key, we recommend the following trusted providers:
You can also use a password manager (1Password, Bitwarden, etc.) that supports Passkeys to generate and store your Passkey.
How to set up a Passkey
- Navigate to the Passkeys section on the Security Settings page.
- Enter a descriptive Name for your passkey (e.g., "My Laptop" or "Yubikey").
- Click Create and follow your browser or operating system's prompts to register the passkey. If prompted by your device, interact with your security key or biometric scanner to finalize the registration.
Done! You can now use the Passkey to log in to your WhatPulse account.
Login
On the login page, click the "sign in with a passkey" link, and follow the instructions to authenticate using your Passkey.

2FA Authenticator app
If you prefer not to use passkeys, you can use a software-based authenticator app on your computer or mobile device to generate time-based verification codes. To learn more about why this layer of security is important, see the Wikipedia article on Multi-factor authentication.
We highly recommend using an authenticator app that supports cloud synchronization so you do not lose access to your account if you lose your device.
Open-Source options:
- Proton Authenticator: An open-source 2FA app available for iPhone, iPad, Apple Watch, Mac, Android, Linux, and Windows. It automatically syncs between all your devices.
- 2FAS: An open-source, community-driven authenticator app that supports secure cloud synchronization via iCloud or Google Drive, as well as a browser extension for seamless desktop logins.
Closed-Source options (with synchronization):
- Authy: Offers encrypted synchronization between Android and iOS devices.
- Google Authenticator: Supports online cloud backups via your Google Account and allows for easy export of tokens.
- Bitwarden: A password manager that also supports TOTP and Passkeys, with cloud synchronization across devices.
How to set up an Authenticator App
- Navigate to the Authenticator app section on the Security Settings page.
- A modal window will appear displaying a QR code.
- Open your preferred authenticator app and select the option to scan a QR code, then scan the code shown on the screen.
- The app will generate a 6-digit verification code. Enter this code into the Verification Code field on the WhatPulse website.
- Click Enable 2FA to finalize the setup.



Once successfully enabled, you will see an "Enabled" badge next to the Authenticator app section.
Log in
Once you've enabled 2FA in your dashboard, go ahead and log out and log back in to give it a try. First, log in normally using your email address and password. Then you'll be prompted for a One-Time Password code. Copy and paste the generated code by your manager (i.e. Google Authenticator or 1Password) and click the VERIFY button to finish your login.

Account Recovery
We strongly recommend using a cross-device syncing authenticator app to prevent getting locked out. However, if you lose access to your primary 2FA method, you can reset your 2FA by doing a password recovery. You'll be required to confirm via an email before that happens.