Manage two-step verification

Review your sign-in methods, enable an available second step and keep track of devices with account access.

Check your login methods

Open Settings → Security → Two-step verification. The Login methods area shows your login email and whether a login phone has been added.

Make sure you can access the email or phone you plan to use. An SMS verification method requires a login phone first. Follow the portal’s verification prompts when adding or changing a login method.

Open security settings

Choose an available verification method

Authenticator app
Select Enable beside Authenticator app and complete the setup shown in the portal. Keep any setup information private.
SMS
Add and verify the login phone through the portal before setting up SMS verification.
Email code
Select Enable beside Email code and complete the instructions sent through the portal’s verification flow.

Follow the current prompts through completion. Starting setup is not the same as enabling a method: return to this screen and check the displayed status.

Review signed-in devices

Open Security → Active sessions to review account sessions. If you choose to sign a device out, make sure you understand which device will lose access.

For team members, use their own accounts and appropriate permissions. Sharing the owner’s login makes it harder to control access or identify who changed a setting.

Open Security → Team activity to review recorded team sessions. Filter by team member, period and activity type: changes, security, views or calls. Concurrent logins are separate sessions; the owner’s own session is excluded from this team view.

Agents & SIP accounts

Review connected sign-in providers

Open Security → Connected sign-in to manage Google or GitHub connections. A connected provider is another way to sign in; your IllyVoIP password remains separate.

Follow the identity-confirmation steps shown in the portal. Removing the final connected provider requires your current password. Connected sign-in does not replace reviewing your two-step verification settings.

If a verification method is unavailable

Use another method only if it has already been configured and the sign-in screen offers it. If you cannot complete verification, contact support through the official contact page and describe the point where sign-in stops.

Include the method involved and the error message. Never send your password, a one-time verification code, an authenticator setup code or an API key in the request.

Contact support

Keep calling and integration credentials separate

Two-step verification protects portal sign-in. It does not replace SIP credentials, API keys or webhook signing secrets. Keep each credential in the system that needs it, and review integrations separately when access changes.

Account security overview

SIP account guide