Two-Factor Authentication and Account Security
Why Use Two-Factor Authentication
Two-factor authentication (2FA) adds a second verification step when you log in. Even if someone obtains your password, they cannot access your account without the second factor. For a platform that manages your business presence, this extra protection is strongly recommended.
Setting Up 2FA
- Go to your Profile page.
- Find the Two-Factor Authentication section.
- Click Enable.
- A QR code will appear on screen. Open your authenticator app (such as Google Authenticator, Authy, or Microsoft Authenticator) and scan the code.
- Enter the 6-digit code from your authenticator app to confirm the setup.
- You will be shown 8 one-time recovery codes. Save these somewhere safe. They are your backup if you lose access to your authenticator app.
Logging In with 2FA
After 2FA is enabled, the login process adds one more step. After entering your email and password, you will be asked for the 6-digit code from your authenticator app. Enter the current code to complete your login.
Recovery Codes
If you lose access to your authenticator app (for example, if you get a new phone), you can use a recovery code instead of the 6-digit code. Each recovery code can only be used once. After using a code, the remaining count is shown so you can keep track.
If you run low on recovery codes, disable 2FA and re-enable it to generate a new set.
Disabling 2FA
To turn off two-factor authentication, go to your Profile page and click Disable in the 2FA section. You will need to confirm your password. After disabling, you will only need your email and password to log in.
Active Sessions
Your Profile page also shows all devices and browsers currently logged into your account. Each session displays the IP address, browser, operating system, and when it was last active. If you see a session you do not recognize, log it out immediately and consider changing your password.
Deleting Your Account
If you need to permanently close your GBPCentral account, the option is at the bottom of the Profile page. You must confirm your password. Account deletion is permanent and cannot be undone. All your data, including posts, analytics, templates, and connected accounts, will be removed.