Sharing 2FA codes at work
Hosting, e-commerce, advertising, the bank: shared accounts have a single verification code, and that code lives on one person’s phone. Here is how companies really share it, and what to do instead.
In short
- The most common methods (turning 2FA off, screenshotting the QR code, pasting codes in chat) leave traces that are hard to revoke.
- Password managers treat the code as an accessory of the password; FloQ generates it on the server, per person, with a log of every use.
- Since July 2025 the NIST guidelines classify SMS codes as “restricted” authentication.
How codes get shared
| FloQ | Other tools | |
|---|---|---|
| Where the codes are generated | On the FloQ server: the key never reaches any phone | On the device or in the shared vault |
| Who sees them | By role or by person, use only or manage | Whoever has access to the shared item |
| Log of every use | Yes | Only in the dedicated services |
| Unlocking | Face ID or Touch ID on iPhone | Depends on the manager |
| In the same app as the team | Yes, next to mail and chat | No: a separate app |
| Password management | No: FloQ is not a password manager | Yes, in password managers |
| Price | Free during early access | 1Password $8.99 and Bitwarden $4 per user per month (25 September 2026); dedicated services vary |
Figures from public pages, 25 September 2026: check the vendors’ sites for current prices.
Where FloQ is different
- The code reaches only who is entitled to it and every copy is written in the activity log.
- Whoever leaves the team loses access without the account’s key having to change.
- It is in the app the team already works in: no dedicated phone in the office, no codes in chat.
Where the others are stronger
- Password managers also keep passwords, notes and documents, and plug into the browser.
- They have years of security reviews and public audits.
- They are useful outside the team’s work too.
When FloQ fits
If the problem is the codes of shared accounts and you want nobody to keep them on a personal phone, FloQ solves it in the same app as mail and chat. For passwords, use a dedicated manager: the two tools complement each other.
Frequently asked questions
Are FloQ’s codes generated on the server?
Yes. The secret key stays encrypted on the server, with a different key for each team: it never reaches anyone’s phone.
Can I import an account from another authenticator?
You add it from its QR code or its secret key. There is no import from other authenticators’ files.
What happens when someone leaves the team?
Remove them from the team or from the sharing rule: they no longer see the codes and the account’s key does not need to change.
Other comparisons
Sources: nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63B-4.pdf · support.1password.com/one-time-passwords · bitwarden.com/help/integrated-authenticator
Try FloQ with your team
FloQ is free during early access. Download it, create your team and connect your first mailbox in a couple of minutes.