Help Center · Account & security
Authenticator apps
An authenticator app is the method we recommend for two-step verification. The app lives on your phone and makes a new 6-digit code every 30 seconds. It works without cell signal, and nothing is texted or emailed to you.
Apps that work
Any standard authenticator app works with Composed Studio. If you already use one for other accounts, use that. If not, Microsoft Authenticator, Google Authenticator, Authy, 1Password, Bitwarden, and the Passwords app built into iOS are all good choices.
Setting it up
Confirm it's you
Open the account menu, choose Sign-in & security, and choose Set up next to Authenticator app. We'll ask for your password before anything else.
Connect your authenticator app
Open the app on your phone, choose to add an account, and point your camera at the square code on the screen. The app will add an entry called Composed Studio. Can't scan? Choose Enter this key instead and type the key shown, in groups of four characters, into your app by hand.
Enter the code from your app
Type the 6-digit code your app is showing for Composed Studio. If it changes while you're typing, just enter the new one. When it's accepted, we'll show you your recovery codes. Save them and tick the box to confirm before you choose Done.
Signing in with it
After your password, we'll ask you to open your authenticator app and enter the 6-digit code for Composed Studio. Codes change every 30 seconds, so if one is about to expire, wait for the next one. If you also set up text or email codes, there's a link on that screen to use one of those instead.
Getting a new phone
Do this before you wipe or hand over the old one: on the new phone, install your authenticator app, then go to Sign-in & security, turn the authenticator app off, and set it up again by scanning the new code. Some apps (Authy, 1Password, Bitwarden, Microsoft Authenticator with backup turned on) can move your entries across for you; if yours does, that works too.
Old phone already gone? Sign in with a recovery code, then set the authenticator app up again on the new phone from Sign-in & security. If you don't have a recovery code either, read lost access to two-step verification.
Codes not accepted?
Nearly every time, it's one of these:
- Your phone's clock is off. Codes are computed from the time, so the phone and our servers have to agree on it. In your phone's settings, make sure date and time are set automatically.
- The code rolled over while you were typing. Wait for the next one and enter it straight away.
- Wrong entry in the app. If you use the app for several accounts, make sure you're reading the one labeled Composed Studio.
Keep it private
The square code and the key behind it are the secret that makes your codes work. Treat them like a password: don't screenshot the setup screen, don't share the key, and don't paste it anywhere except into your authenticator app. If you think someone else may have it, turn the authenticator app off in Sign-in & security and set it up again. That gives you a new key and makes the old one useless.
Bring us the problem everyone works around.
If your team burns hours on work that software should be doing, tell us about it. One of our products may already cover it. If not, we'd like to hear what's missing.