How to enable 2FA on OneLogin
- Sign in to your OneLogin account.
- Open Account settings → Security (the exact path varies; see the official docs link above).
- Choose your preferred method from the list — TOTP and hardware keys are the recommended options.
- For TOTP: scan the QR code with Kaito or your authenticator app of choice. Verify the first 6-digit code before saving.
- For hardware keys: insert your key when prompted and tap to enroll. Register at least two keys per account so loss of one doesn't lock you out.
- Save the recovery codes somewhere safe — they're your last resort if you lose your authenticator and your hardware keys.
Hardware keys supported
OneLogin documents support for: Yubico OTP.
Sharing OneLogin 2FA with a team (with Kaito)
Kaito gives you a vault for shared TOTP and a real-time inbox for shared SMS, with per-token group permissions and an audit log on every code view. To share OneLogin access with your team:
- In Kaito, go to Tokens → New and add the OneLogin 2FA seed (or scan the QR).
- Permission the token to a group:
code-onlyfor most teammates,full-seedonly for the admins who would handle rotation. - Stream the audit log to your SIEM if you want a complete record of which team members generated codes for OneLogin and when.
Note: OneLogin's terms on account sharing are unclear or grey-area. Many teams share access in practice; doing so via Kaito gives you a clean audit trail if it ever becomes a question.
Frequently asked questions
Does OneLogin support 2FA?
Yes. OneLogin supports 2FA via Custom app, SMS, TOTP, Custom hardware, Hardware key.
What is the most secure 2FA method for OneLogin?
A hardware security key (Yubico OTP) is the most phishing-resistant option OneLogin supports. Use TOTP as a fallback.
Can I share OneLogin 2FA with my team?
OneLogin's terms on account sharing are grey-area. Many teams share access in practice; using Kaito gives you a clean audit trail if it ever becomes a question.
How long does it take to enroll OneLogin 2FA in Kaito?
Under two minutes. Open the OneLogin security settings, scan the QR code with Kaito's add-token flow, and verify the first generated code matches.