Skip to content

Account & Settings

Turn on two-factor authentication

Add a second step to your Calso sign-in — a 6-digit code emailed to you — including how Calso makes you prove the code arrives before it switches anything on, and what to do if you lose access to that inbox.

Updated August 27, 2026

Two-factor authentication puts a second lock on your Calso account: after your password, Calso emails you a 6-digit code and waits for it before letting anyone in. Your account holds your client list, your session notes, and your payout details, so the two minutes this takes is a fair trade.

It lives in one place. Open Settings from the sidebar and choose the Security tab — the last one in the row across the top. The single card there is headed Two-factor authentication, and it tells you the exact email address your codes will go to. Read that address before you go any further: it is the only place a code will ever be sent.

What changes about signing in

Once two-factor is on, the email-and-password sign-in gains one extra screen. You type your email and password as usual, and instead of landing on the dashboard you land on a short screen headed Confirm your sign-in asking for the code that has just been emailed to you.

It applies to that password sign-in and nothing else. If you use Sign in with Google or Sign in with Microsoft, those sign-ins are unaffected — Google and Microsoft already run their own second step, and Calso does not stack a second one on top. You are also only asked for a code when you actually sign in, not every time you open the dashboard, so on a computer you use every day this is a rare interruption rather than a daily one.

Turning it on

Calso will not switch two-factor on until a code has genuinely reached you. The button sends a test code first and only enables the setting once you type that code back in, which is what stops a stale or mistyped address from locking you out of your own account.

  1. Open the Security tab

    From the sidebar, open Settings, then choose Security from the tabs across the top of the page. Check the email address named in the Two-factor authentication card is one you can still open today — every future sign-in will depend on it.

  2. Send yourself a test code

    Click Turn on two-factor. Calso emails a 6-digit code to that address straight away and the card swaps to a code box. Nothing has been switched on yet at this point, so if you change your mind you can click Cancel and the setting stays exactly as it was.

  3. Enter the code and enable

    Open the email — the subject is "Your Calso sign-in code" — and type the six digits into the box, then click Verify and enable. The code is good for ten minutes, and after five wrong attempts it stops working, in which case click Cancel and Turn on two-factor again for a fresh one.

  4. Check the confirmation

    The card confirms with Two-factor authentication is now enabled. and the button changes to Turn off two-factor. Nothing signs you out — the session you are in right now carries on, and the code is asked for the next time you sign in from scratch.

Signing in with a code

The next time you sign in with your password, the Confirm your sign-in screen asks for a Sign-in code. Type the six digits from the email and click Verify code.

Two other controls sit under that box. Send a new code issues a fresh one, and becomes clickable again about thirty seconds after the last one went out — until then it counts down so you can see when it will free up. ← Back returns you to the email and password fields, which is what you want if you typed the wrong email address in the first place.

When a code is refused

Codes are deliberately short-lived, and the sign-in screen names the reason when one is turned down. "That code has expired" means more than ten minutes passed; request another with Send a new code. "Too many wrong codes" means that particular code has been retired after repeated wrong entries, and again a new one clears it. "That code didn't match" is simply a typo — check you are reading the most recent email, since an older code stops being valid as soon as you request a replacement.

If you ask for several codes in quick succession you may be told to wait a few minutes. Calso keeps only a small number of live codes per account at once, and they expire on their own, so a short wait is all that is needed.

If you lose access to the email

This is the one thing worth thinking about before you switch two-factor on. Calso's second factor is an emailed code and nothing else — there is no authenticator app to scan and no sheet of backup codes to file away — so access to that inbox is what stands between you and your account.

If you still have a session open somewhere, that is your way back in. Open Settings, go to Security, and use Turn off two-factor before that session ends. If you are locked out completely, email support@calso.io and ask for two-factor to be cleared from your account; Calso can do that once your identity is confirmed. Do not count on a password reset to rescue you — the reset link is sent to the same address the codes go to.

Turning it back off

The same card handles it. Click Turn off two-factor, confirm when your browser asks, and the card reports Two-factor authentication has been turned off. Your password alone will sign you in from then on, and you can switch it back on later with the same test-code flow.

With your account locked down, the other thing worth knowing about is what has been happening inside your workspace — see review your workspace audit log. If you also give clients a signed-in area of their own, that is a separate sign-in with its own settings: see turn on the client portal.

Frequently asked questions

Do I still need a code if I sign in with Google or Microsoft?

No. Two-factor in Calso only covers the email-and-password sign-in. If you use the Sign in with Google or Sign in with Microsoft buttons, that provider already runs its own second step and Calso does not add another one. Turning two-factor on is only worth doing if you actually sign in with a password — and if you sign in both ways, the code is asked for on the password route only.

The sign-in code email never arrived. What do I do?

Check your spam folder first — the code comes from the same address your booking emails do, bookings@calso.io, with the subject "Your Calso sign-in code". On the sign-in screen you can use Send a new code, which becomes available again about thirty seconds after the last one. If you ask for several in a row you may be told to wait a few minutes; Calso only keeps a small number of live codes per account at a time, and they clear themselves once the ten minutes are up.

What happens if I lose access to the email address my codes go to?

You will not be able to finish signing in with your password, because there are no backup codes and no authenticator app to fall back on. If you are still signed in on another computer or phone, go straight to Settings, open the Security tab, and use Turn off two-factor while you still have a session. If you are locked out entirely, email support@calso.io — Calso can clear two-factor on your account once your identity is confirmed. Resetting your password will not help on its own, since the reset link goes to the same inbox.

Does two-factor change how my clients sign in?

No. It protects your own Calso account only. Clients booking on your public page are never asked for a code, and clients signing in to the client portal use their own separate sign-in, which this setting does not touch.