Two-factor authentication adds a second verification step at login, beyond your password. Even if your password is compromised, an attacker can't get into your account without the code from your authenticator app.
2FA is available on both the web app and the iOS app.
Go to Account → Security
Click Enable Two-Factor Authentication
Scan the QR code with your authenticator app (Google Authenticator, Authy, 1Password, or any TOTP-compatible app)
Enter the 6-digit code from your app to confirm
Save your backup codes somewhere safe — you'll need them if you ever lose access to your authenticator
Open the Hello Hotel app
Go to your profile and tap Security
Tap Enable Two-Factor Authentication
Follow the prompts to link your authenticator app
Confirm with a 6-digit code
After 2FA is enabled, every login asks for your authenticator code after your password. The code rotates every 30 seconds — use the current one.
When an admin signs in, Hello Hotel can deliver the 2FA challenge code via three channels:
Authenticator app (recommended) — the most secure option, doesn't depend on phone or email reachability
SMS — the code is texted to the phone number on file for that admin
Email — the code is emailed to the address on file for that admin
SMS and email are useful as a fallback when an admin doesn't have an authenticator set up, or when they've lost access to their authenticator app and need to log in quickly. The authenticator app stays the safer choice for day-to-day use.
If you lose your phone or your authenticator app, use one of your backup codes to log in. Each backup code works once. Generate a new set of backup codes from Account → Security after using one.
If you don't have backup codes and can't access your authenticator, contact your organization admin or reach out to Hello Hotel support to verify your identity and reset 2FA.
Use an authenticator app, not SMS. Authenticator apps are more secure than SMS-based 2FA because they don't depend on your phone number being available.
Print or save backup codes immediately. The most common 2FA lockout is losing the authenticator without saving backups. Print the codes or store them in a password manager.
Enable 2FA on every account that supports it. Hello Hotel, your email, your PMS, your bank — 2FA is one of the highest-leverage security steps you can take.