Verified Wavize guide

Enable email two-factor authentication

Add a temporary code after the password to protect the owner account.

Updated 7 August 2026

Client email two-factor is optional and off by default

The owner may enable protection under Settings > Security. Wavize requests the current password before any change so an open session cannot silently enable or disable the control.

After activation, password sign-in triggers a six-digit code sent to the owner address. The code lasts ten minutes. Partner accounts follow another rule: email code is required at every login after password.

Administration boundary
A team member cannot enable or disable owner 2FA. The endpoint denies action when a member identity is active in session.

Prepare activation

First secure the inbox receiving codes.

  1. Durable email access

    Use an organization-controlled inbox with its own strong protection and up-to-date recovery methods.

  2. Deliverability

    Allow the Wavize sender and check spam/quarantine. Do not enable just before urgent work without testing delivery.

  3. Current password

    Even if you usually sign in with Google, the form requires current local password. Use Forgot password if you never set one.

Enable from settings

In the Email two-factor card, enter password and confirm.

  1. Incorrect password response

    The setting remains unchanged and form returns a 422 error. Do not retry repeatedly; verify account or reset password.

  2. Enabled state

    Activation date is stored and card badge changes. Sign out to immediately run a login test.

  3. Latest code

    Enter exactly six digits within ten minutes. After resending, use the latest message and ignore previous ones.

Disable without leaving active codes

Disabling also requires current password.

  1. Confirm identity

    Open owner session, enter password and choose Disable. A member session is denied.

  2. Code cleanup

    Wavize deletes stored web-login codes for this address so an old email cannot complete a flow.

  3. Post-disable test

    Sign out then sign in by password. Dashboard should open without code stage; securing the inbox remains recommended.


When code does not arrive

Never share a complete code with support.

  • Wait then resend — Avoid several rapid requests and use only latest code.
  • Check filtering — Spam, quarantine, rules and mailbox capacity.
  • Support — Provide time, masked address and error message, never password or code.