Security & privacy

Two-factor authentication with an authenticator app

A password alone is not enough for a tool that can change ad budgets. Two-factor authentication adds a one-time code from your phone.

What it does

The service uses standard time-based codes (TOTP): 6 digits, a new code every 30 seconds, compatible with Google Authenticator, 1Password, Authy and similar apps. When you enable it, you get the secret and an otpauth link to add to your app, plus 10 backup codes shown once. Each code works exactly once.

With 2FA, sign-in has two steps: the password gives a short challenge, the code gives the session. Sensitive actions ask for a code again: approvals, role and assignment changes, deactivation, invitations, the emergency stop, API key creation, enabling auto policy and turning off 2FA itself. For owners and admins, 2FA is required to perform these actions.

Why it helps

  • Stolen passwords are not enough to change your ads.
  • Every sensitive action is confirmed by a person with a device.
  • Backup codes prevent lockouts.

How to set it up

  1. Open Settings → two-factor authentication.
  2. Add the secret to your authenticator app.
  3. Enter a code to confirm and save the backup codes somewhere safe.
  4. Use codes when signing in and approving changes.

Good to know

  • Store backup codes offline; each can be used once.
  • Turning 2FA off requires both the password and a code.
Ace, the AdAce Ads mascot

Try it on your own accounts

Create a workspace, connect Google or Meta in a couple of clicks and see your accounts clearly. Changes follow your approvals or the policy you configure.

Create your workspace