How to turn on two-factor authentication for my client area
Your client area controls your domains, hosting logins, invoices and support tickets. Anyone who gets in can transfer domains away or open a ticket in your name. Two-factor authentication (2FA) means logging in needs your password and a code from your phone.
This guide covers the client area at portal.webway.host.
What you need
An authenticator app on your phone: Google Authenticator, Microsoft Authenticator, Authy, or the one built into a password manager such as Bitwarden or 1Password.
Turn it on
- Log in to the client area at portal.webway.host.
- Click your name in the top-right corner and choose Security Settings.
- Under Two-Factor Authentication, click Click here to Enable.
- Follow the prompts to set up an authenticator app.
- Open your authenticator app and scan the QR code. If you can't scan, type the code shown under the QR code into the app instead.
- Enter the six-digit code the app now shows and click Submit.
- Save the backup code that appears. Write it down or store it in your password manager. It's the only way in if you lose your phone, and it's shown once.
From now on, after your password you'll be asked for the current code from the app.
Logging in with 2FA
- Enter your email and password as usual.
- Open the authenticator app and type the six-digit code for Webway. Codes change every 30 seconds; if one is refused, wait for the next.
Lost your phone or changed phones?
- Backup code: on the 2FA prompt, enter your backup code instead of an app code. Once in, disable and re-enable 2FA to link the new phone and get a fresh backup code.
- No backup code: open a ticket from the email address on the account. We'll verify your identity before removing 2FA. This takes time, which is why the backup code matters.
Turn it off or reset it
- Security Settings → Two-Factor Authentication → Click here to Disable.
- Enter your password to confirm.
To move to a new phone, disable then enable again and scan the new QR code.
Other things worth doing on the same page
- Change password: use a long, unique password. Never the same as your email or control panel password.
- User Management (under your name): if a colleague or developer needs access, invite them as their own user with limited permissions rather than sharing your login.
Common problems
| Problem | Fix |
|---|---|
| "Invalid code" every time | Your phone's clock is off. Turn on automatic date and time in the phone's settings |
| No QR code shows | Try another browser or disable ad-blockers for the page |
| App shows codes for the wrong account | You may have scanned a QR code for another site. Delete the entry and re-enable 2FA to get a fresh code |
| Locked out completely | Use the backup code, or open a ticket from the account email |
Did this answer it?