Authenticator App - Novaz

Odoo 2FA: How to Set Up an Authenticator App

odoo.com SupportedChecked against official help · September 25, 2026

Your Odoo account opens your company's Odoo database, with its sales, invoices, contacts and every other app your company runs. Odoo calls the feature two-factor authentication (2FA): an authenticator stores a secret and gives you a code to enter when you log in, so Authenticator App - Novaz can supply your codes.

A Odoo account can be tied to your money and personal finances, so a stolen password is a direct financial risk. Odoo secures sign-ins with an authenticator app — set it up once and you're protected on every login.

2FA methods Odoo supports

  • Authenticator app (TOTP)

Before you start

  • Your Odoo username and password (Odoo asks you to confirm the password before it shows the QR code)
  • Authenticator App - Novaz installed on your iPhone or iPad
  • Odoo open on a computer, so the QR code is on a different screen from your phone. If you set up on the same device, you'll use the "Cannot scan it?" link instead
  • The name of your database administrator: Odoo's documentation doesn't describe backup codes, and only an administrator can deactivate 2FA if you lose your authenticator

Part 1: Turn on 2FA in Odoo

  1. 1

    Open My Preferences

    Log in to Odoo, click your profile avatar in the upper-right corner and select "My Preferences" from the drop-down menu.

  2. 2

    Click Enable 2FA

    Click the "Security" tab, then click "Enable 2FA".

  3. 3

    Confirm your password

    An "Access Control" pop-up window asks you to confirm your password. Enter your Odoo password and click "Confirm Password". A "Two-Factor Authentication Activation" window opens with a QR code.

Part 2: Add Odoo to Authenticator App - Novaz

  1. 4

    Scan the QR code in Authenticator App - Novaz

    Open Authenticator App - Novaz, tap the + button and scan the QR code. If you can't scan the screen, click "Cannot scan it?" in Odoo, choose to enter a setup key in the app and type the code Odoo shows. Check the account name, then tap "Save".

  2. 5

    Note the verification code

    Authenticator App - Novaz now shows a verification code for Odoo. Have it ready for the next step.

Part 3: Confirm and finish

  1. 6

    Click Enable Two-Factor Authentication

    Back in Odoo, enter the code in the "Verification code" field and click "Enable Two-Factor Authentication".

  2. 7

    Log out and test it

    Log out of Odoo. On the login page, enter your username and password and click "Log in". On the "Two-factor Authentication" page, enter the current code from Authenticator App - Novaz in the "Authentication Code" field and click "Log in".

  3. 8

    Save a way to recover your account

    If Odoo offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how Odoo recovers accounts before you need it.

If something goes wrong

  • Odoo rejects the verification code: enter the newest code from Authenticator App - Novaz, and make sure your iPhone sets its date and time automatically (Settings > General > Date & Time).
  • You're setting up Odoo on the same iPhone that runs Authenticator App - Novaz: you can't scan your own screen, so click "Cannot scan it?" and add the code manually.
  • Odoo keeps asking you to log in and enter a code: session or inactivity timeout policies on one of your user groups may be the cause. Administrators can review them in the "Timeouts" settings on user groups when the auth_timeout module is installed.
  • You can't turn 2FA off: some governments, such as Australia's, require 2FA, and in those fiscal localizations it can't be deactivated.
  • You've lost the phone with Authenticator App - Novaz: you can't log in until an administrator deactivates 2FA on your account.

Checked against Odoo's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:

How to recover your Odoo account

Odoo's documentation doesn't describe backup or recovery codes. If you lose access to Authenticator App - Novaz, an administrator must deactivate 2FA on your account before you can log in again. Once you're back in, set it up again from "My Preferences" > "Security" > "Enable 2FA" and scan the new QR code. Because the docs describe no self-service fallback, check who can administer your database before you rely on 2FA.

Frequently asked questions

Which authenticator apps work with Odoo?
Odoo lists phone authenticators such as Authy, FreeOTP, Google Authenticator, LastPass Authenticator and Microsoft Authenticator, and password managers such as 1Password and Bitwarden, as examples rather than endorsements. Authenticator App - Novaz works the same way.
Can an administrator make 2FA mandatory?
Yes. In the "Settings" app, in the "Permissions" section, tick "Enforce two-factor authentication", choose "Employees only" or "All users" (which also covers portal users), then click "Save".
Does Odoo give me backup codes?
Odoo's documentation doesn't mention any. If you lose your authenticator, an administrator has to deactivate 2FA on your account.
Why can't I deactivate 2FA?
Some governments require 2FA. For those fiscal localizations, such as Australia, it isn't possible to deactivate it.

Generate your Odoo codes in Authenticator App - Novaz

Free, offline, and encrypted. One tap for every 6-digit code.

Get the app

More Finance guides

Novaz is not affiliated with, endorsed by, or sponsored by Odoo. Odoo and its logo are trademarks of their respective owner and are used here for identification only.