Multi-Factor Authentication (MFA) on Warp

Last updated: July 27, 2026

Multi-factor authentication adds a second step when you log in to Warp. In addition to your password, you'll confirm it's really you with a second factor, usually a code from your phone. That way, even if your password is ever stolen, phished, or leaked in a breach somewhere else, no one can access your Warp account without that second factor.

Why we recommend enabling MFA across your organization

Passwords alone are the weakest link in account security. MFA fixes it.

Payroll accounts are a favorite target for attackers, and the playbook is well documented. The FBI has repeatedly warned about payroll diversion scams, where criminals phish an employee's login credentials, sign in to their payroll account, and quietly reroute their direct deposit to an account they control. The FBI's recommended defense for exactly this scheme: multi-factor authentication.

Employers: How to set up MFA

  1. Go to Security

  2. Toggle on Require MFA

  3. From then on, logging in takes one extra step for all users - password, then second factor.

Employers & Employees: How to set up MFA

  1. Log in to Warp via app.joinwarp.com

  2. The first time MFA is enabled for your org, you'll be prompted to scan a QR code with an authenticator app of your choice (e.g., Google Authenticator, Authy, 1Password).

  3. Open your authenticator app and scan the QR code. A new entry will appear labeled Warp, followed by your email address, along with a 6-digit one-time code.

  4. Enter that code into the field provided on the Warp login screen to complete setup.

Once MFA is enabled, you'll be prompted to enter a new code from your authenticator app each time you log in.

MFA best practices

Not all MFA is equally strong. A few habits make yours as effective as possible:

  • Never share a verification code with anyone. Not with a coworker, not with IT, and not with anyone claiming to be from Warp. We will never ask you for a code. Anyone who does is trying to break into your account.

  • Deny prompts you didn't ask for. If you ever get a login verification you didn't initiate, deny it. Attackers sometimes flood users with repeated prompts hoping one gets approved out of annoyance, a tactic known as push bombing. An unexpected prompt usually means someone already has your password, so deny it, change your password right away, and let your admin know.

Password best practices

MFA protects you when your password fails, but a strong password matters too. Current guidance from NIST and CISA is simpler than the old rules:

  • Longer beats more complicated. Aim for at least 16 characters. A passphrase of four or more unrelated words (like "coral-tundra-billiard-sprint") is both stronger and easier to remember than "P@ssw0rd1!".

  • Use a unique password for every account. Reusing passwords means one leaked site becomes a master key to everything else, including your payroll. This is the single most important rule.

  • Use a password manager. Tools like 1Password generate and remember strong, unique passwords for you, so you only have to remember one.

Frequently asked questions

What if I lose my phone?

Use one of the backup codes you saved during setup to log in, then register a new device from your authenticator app. If you've lost both your phone and your backup codes, contact support@warp.co / your company admin to verify your identity and restore access.

Can my company turn MFA off?

Admins can disable the MFA requirement company-wide in Security. We strongly recommend against it and suggest treating it as a last resort for a specific, temporary need.

Does this change anything about my pay or benefits?

No. MFA only changes how you log in. Everything in your account stays exactly where it was.

How does Warp protect my data?

MFA is one layer in how Warp secures your information. You can learn more at warp.co/security and our Trust Center.


Questions? Please reach out to us at support@warp.co.