Account Security

Is 2FA mandatory?

If you've been prompted to set up or verify two-factor authentication (2FA), this article explains what it is, why Zeffy requires it, and when it applies to your account.

What is two-factor authentication (2FA)?

Two-factor authentication adds a second verification step to protect your account. Instead of only entering your password, you also enter a short code sent to your phone - either by text message (SMS) or through an authenticator app.

This means that even if someone learns your password, they still can't access your account without that second code.

Why does Zeffy require 2FA?

Zeffy accounts are directly connected to your nonprofit's fundraising activity β€” including payments, bank account details, and sensitive donor data. That makes account security especially important.

2FA protects:

  • Your organization's funds and payout settings

  • Your donors' personal and payment information

  • Your ability to receive and manage donations

Zeffy requires 2FA to reduce the risk of unauthorized access. Without it, a compromised password could expose everything your organization has built.

Note that two-factor authentication (2FA) is currently only mandatory when changing banking information on the account. It is not required when logging in from a new device, although we strongly recommend enabling it there as well for additional security.

When am I asked for a 2FA code?

2FA is not required every time you log in. You'll be prompted for a code when:

  • You are setting it up for the first time

  • You are updating your bank account or payout information (mandatory)

  • You are logging in from a new device or browser (only if enabled in your settings)

Everyday logins on your usual device typically don't require a code β€” just your email and password.

Is 2FA mandatory for everyone?

Yes. 2FA is required on all Zeffy accounts. It applies to every user individually β€” each person on your account sets up their own 2FA tied to their own phone number. There is no account-wide toggle to disable it.

If you're being asked to complete 2FA setup and it feels unexpected, it's most likely because you're updating sensitive information like bank details, or logging in from a device Zeffy doesn't recognize.

What if I don't have a US, Canadian, or UK phone number?

SMS codes can only be delivered to phone numbers from countries where Zeffy operates. If your number is from another country, you can still use it in Zeffy. Below is a list of countries supported for 2FA verification.

Alternatively, you can use an authenticator app instead – it works on any phone, anywhere in the world, without requiring a phone signal.

Was this helpful?