Set up two-factor authentication with 1Password
Protect your OutcomeCI account with an authenticator code, save it in 1Password, and keep recovery codes for when you need them.
Two-factor authentication adds an authenticator code to password and GitHub sign-in. OutcomeCI supports standard time-based one-time passwords (TOTP), so you can use 1Password or another authenticator app.
Enable two-factor authentication
- Sign in to OutcomeCI and open Account security.
- In Two-factor authentication, select Set up.
- Verify your identity using the method shown. Depending on your account, this may be your password, an email verification code, or a registered passkey.
- When Set up your authenticator appears, scan the QR code with your authenticator app. You can also enter the displayed setup key manually.
- Enter the current code from your authenticator and select Enable two-factor authentication.
- Save your recovery codes before closing the dialog. They are shown only once, and each code can be used once.
The account security page now shows two-factor authentication as On. Changing your account security settings signs out your other sessions.
Save the code in 1Password
Save an OutcomeCI Login item in 1Password with https://outcomeci.com as its
website before you start enrollment.
When OutcomeCI displays the setup QR code:
- Unlock the 1Password browser extension and select your OutcomeCI Login item.
- Open the item's menu and choose Scan QR Code.
- Use the generated one-time password to finish enrollment in OutcomeCI.
1Password may offer to save the code automatically when it recognizes the QR code and an existing Login item. If no prompt appears, use Scan QR Code manually. See 1Password's authenticator setup instructions for other devices and manual setup.
Keep the setup key and QR code private: either can generate your sign-in codes.
Sign in with two-factor authentication
After signing in with your password or GitHub, enter the current code from 1Password or your authenticator app when prompted. If a code expires, use the next one displayed by the app.
A registered passkey provides its own device verification and does not require an additional authenticator code.
Use a recovery code
If you lose access to your authenticator, enter one of your saved recovery codes in the authenticator-code field at sign-in. Each recovery code works only once. Store the remaining codes somewhere secure that you can access if your authenticator is unavailable.
Once signed in, open Account security to update your authentication methods. You must verify your identity again to make changes. Turning two-factor authentication off and setting it up again gives you a new setup key and new recovery codes; replace your saved copies.
Turn off two-factor authentication
Open Account security, select Turn off in the Two-factor authentication row, and complete identity verification. Password and GitHub sign-in will no longer require an authenticator code.