We're on Product Hunt today! Leave a comment

Add to Chrome

HubSpot authenticator app

HubSpot two-factor authentication works with any third-party authenticator app, including one in your browser. Click the settings icon → General → Security → “Set up two-factor authentication (2FA)”, choose “Authenticator app”, and scan the QR code from the screen with the Authenticator extension.

A HubSpot login opens your contacts, deals, email sequences and the marketing email that goes out under your company’s name — a stolen password there exposes customers, not just you. HubSpot requires two-factor authentication for everyone who signs in with a password on its Starter, Professional and Enterprise plans, and it recommends an authenticator app over text messages.

Turn on two-factor authentication in HubSpot

On Starter, Professional and Enterprise, HubSpot asks you to set up 2FA at your first sign-in and it cannot be turned off — then the setup starts on its own and you begin at step 4. On free tools, a Super Admin can require it with “Enforce 2FA to log in”, and Super Admins can limit which methods the team may use. If you sign in with Google or Microsoft, HubSpot does not prompt you, but you can still turn it on here.

  1. Sign in to HubSpot on your computer and click the settings icon in the top navigation bar.
  2. In the left sidebar, go to “General” → “Security”.
  3. In the “Two-factor authentication (2FA)” section, click “Set up two-factor authentication (2FA)”.
  4. Choose “Authenticator app” and follow the instructions on the screen.
  5. HubSpot shows a QR code. Leave it on the screen and add it to the extension as described below — then click “Next”, enter the six-digit code and click “Next” again.
HubSpot’s own instructions

Add HubSpot to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the HubSpot page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to HubSpot and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. HubSpot confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on HubSpot’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Save your HubSpot backup codes

Right after the code is accepted, HubSpot shows backup codes — click “Print” or “Download PDF” and keep them somewhere other than this computer. You can see them again under General → Security → “View backup codes”, where “Generate new codes” creates ten new ones and cancels the old set. HubSpot also recommends a secondary method — a second authenticator or text messages — added in the same section.

The code is not accepted?

Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.

If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Do I need the HubSpot mobile app or a phone for 2FA?
No. HubSpot’s “Authenticator app” option takes any app that produces standard six-digit codes — it names Google Authenticator, Authy and Duo. The Authenticator extension generates them in Chrome and reads the QR code straight off the Security page. HubSpot has also paused setting up new 2FA with its own mobile app.
Can I turn off two-factor authentication in HubSpot?
Not on Starter, Professional or Enterprise, where it is required for every password sign-in. On free tools, or where your company requires single sign-on, you can remove it under General → Security — HubSpot recommends keeping it.
What if I lose access to my authenticator?
Use a backup code or your secondary method at the sign-in prompt. Without either, click “Reset authentication device” and request a reset from your Super Admin; if there is none to ask, HubSpot verifies you with a photo ID or through support, which takes at least 48–72 hours. HubSpot support cannot simply turn your 2FA off.
Why does HubSpot say “This doesn’t look right”?
HubSpot’s own answer is the clock: codes are based on the current time, so a clock that is off by a minute produces codes it refuses. Turn on automatic date and time and try the next code. If it still fails, remove the account from the extension and set the authenticator up again.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free