// feature

Role-based access control for shared 2FA

Sharing 2FA shouldn't mean everyone sees everything. 2fashare scopes access by role and by group, so each teammate only ever reaches the codes they actually need.

Three clear roles

Admin runs the workspace, Manager curates groups and membership, and User views and copies the codes they're granted.

Scoped per group

Permissions live at the group level. Add someone to one group and they see exactly that - nothing else in the workspace.

Least privilege by default

New members start with the narrowest access. Widen it deliberately instead of walking back an over-share later.

Access that maps to how your team actually works

Most teams share 2FA the wrong way: one person holds the authenticator and everyone pings them for codes, or the secret gets pasted into a channel where it lives forever. Both break the moment someone leaves.

2fashare replaces that with role-based access control. Every code belongs to a group, every group has members, and every member has a role. Change a role or remove a member and their access updates instantly - no rotating secrets, no cleanup.

Common questions

What can each role do?+

Admins manage the whole workspace and its members. Managers create groups, add codes, and invite people. Users view and copy the codes inside the groups they belong to.

Can one person be an admin on some groups and a user on others?+

Access is scoped per group, so a member's reach is defined by which groups they're in and the role they hold there. You grant exactly what each person needs.

What happens when I change someone's role?+

Role and membership changes take effect immediately. There's no need to rotate the underlying TOTP secret - access is enforced live by row-level security.

Stop screenshotting codes. Start sharing them safely.

2fashare takes ten minutes to set up and is free to get started.