An extra code from your phone when you sign in — and what to do if you lose the phone.
Two-step verification asks for a six-digit code from your phone as well as your password. If somebody learns your password, it is still not enough to get into your account.
You will need an authenticator app. Google Authenticator, Microsoft Authenticator, Authy and 1Password all work, and your phone may already have one.
Turning it on. Go to Settings → Account → Set up two-step verification. Scan the square code with your authenticator app, type the six digits it shows, and it is on. Next time you sign in, Unison asks for your password and then a code.
The codes change every 30 seconds. If one is rejected, wait for the next one and try again — it is usually a clock a few seconds out, not a mistake.
Backup codes — do this straight after you turn it on. Go to Settings → Account → Backup codes. You get ten codes. If you ever lose your phone, one of them gets you back in.
Three things about them:
Print them or write them down, and keep them away from the computer. Anyone with one of these and your password can get into your account, so treat the sheet like a spare key to your house — not a note on your desk.
Also worth doing: set two-step up on a second device as well (a tablet, a partner's phone — scan the same square code with both), or keep the typed key shown under the square code. Then you may never need the backup codes at all.
If you have already lost the phone and have no backup codes, email info@unisonapp.io from the address on your account. It can be removed, but it is a manual job and it is not instant.
Turning it off. Settings → Account → Turn off two-step verification. You will be asked for a current code first — that is deliberate. If it could be switched off without one, anyone who found your laptop unlocked could switch it off and it would have protected nothing.