How to set up a user with two-factor authentication
Set up two-factor authentication
Every TUGDB account is protected by a second step at login: a 6-digit code from an app on your phone. It takes about three minutes to set up — once. Before you start
Install an authenticator app on your phone if you don't already have one. Any of these work:
Proton Authenticator, Google Authenticator, Microsoft Authenticator, NetIQ Auth, Authy. Pick one and stick with it.
Setting it up
1. Set your password. You'll receive an invitation email from TUGDB with a link to choose your password. Click it and set a password you'll remember.
2. Log in. Go to https://tugdb.dk and sign in with your username and the password you just set.
3. You'll land on the 2FA setup page. The first time you log in, TUGDB takes you straight to the two-factor setup page and shows a QR code. Leave this page open.
4. Scan the QR code with your app. Open your authenticator app, choose Add / Scan a QR code, and point it at the screen. The app adds an entry named something like tugdb.dk: yourname.
5. Enter the 6-digit code. Your app now shows a rotating 6-digit code, e.g. 309 214. Type the code currently shown into the setup page and confirm.
Do it in one go. The code changes every 30 seconds. Scan and type the current code on the same page — if you wait too long, just use the next one it shows.
6. Done — that's it. From now on, each login asks for your password and the current 6-digit code from that app entry. Same code source every time.
Four rules that avoid 99% of problems
1. Use one app, one entry. Scan the QR into a single authenticator app. That one entry is your code for every login.
2. Keep your phone clock automatic. Codes are time-based. In your phone's settings, leave date & time set to automatic and the codes always match.
3. Don't Reload the setup page halfway. Refreshing or leaving mid-setup can generate a fresh QR. If that happens, re-scan the new QR and use its code.
4. Don't read a code from an old entry. If you ever re-enroll, delete the previous tugdb.dk entry first. A leftover entry shows codes that will always be rejected.
If something goes wrong
"It keeps asking for the code / the code is rejected." Almost always one of two things: you're reading the code from an old or duplicate tugdb.dk entry, or your phone clock is off. Fix: delete any old tugdb.dk entries so only the newest remains, and check your phone's time is set to automatic. Then try the current code again.
"I switched phones / lost my phone." Your codes live only on the device that scanned the QR, so a new phone needs a fresh setup. Fix: ask your TUGDB administrator to reset your 2FA — you'll then set it up again from step 3 on your new phone.
"I never got the invitation email." Check spam, then contact your administrator to re-send it.