Skip to main content

Multi-Factor Authentication (2FA) Best Practices

Learn best practices for securing your Goodshuffle Pro account with multi-factor authentication (2FA), password managers, and encrypted recovery codes.

Jake Scotto avatar
Written by Jake Scotto
Updated over a week ago

This feature is available on all Goodshuffle Pro Plans.

Good account security protects not only your business but your client data too. There are three key pillars to staying secure online:

  • Always use 2FA through an app

  • Use a password manager

  • Save your backup codes somewhere encrypted

Each layer should exist independently, so if one fails, your account is still protected.


1. Use 2FA Through an App (Not SMS)

While 2FA is always better than no 2FA, text message codes can be intercepted. Instead, use a dedicated authenticator app such as:

🚫 Never back up your authenticator app to your email account. If your email is compromised, so are your 2FA codes.


2. Use a Password Manager

Passwords should be random, complex, and unmemorable. That’s why password managers are key.

Benefits include:

  • Randomized password generation

  • Secure storage across devices

  • Shared vaults (great for families or teams)

🔐 At Goodshuffle, we use 1Password — it even offers family plans!


3. Store Backup Codes Safely (Not in Your Password Manager)

If you lose access to your phone, your 2FA app goes with it.

This is where recovery codes come in — they’re usually provided when you first enable 2FA on a site. These are single-use codes that let you back into your account.

❗ Don’t store these in your password manager. If that’s ever breached, your backup codes would be too.

Instead:


Want to Enable 2FA in Goodshuffle Pro?


Need Additional Support?

Click the blue chat bubble in the bottom corner of your screen to message our support team—we’re happy to help!

Did this answer your question?