Account & security
This page covers how your individual account is secured — signing in, two-factor authentication, and getting back in if you lose your second factor — and what it looks like the first time you accept a crew invite. It’s written for anyone with a Tobren Operations login, not just admins.
Two-factor authentication (2FA)
If you signed up with an email and password, Tobren Operations requires a second factor on top of your password — it’s what keeps your fleet’s records yours alone if your password ever leaks. If you signed in with Google or Apple instead, your account skips this: sign-in security is delegated to that provider.
The first time an email/password account signs in, you’re walked into setup before you can reach the workspace. Choose one of two methods:
- Authenticator app (recommended) — scan a QR code with Google Authenticator, 1Password, Authy, or any TOTP app, then confirm with the 6-digit code it generates. Works without cell service.
- Text message — get a 6-digit code by SMS each time you sign in.
Once enabled, every sign-in asks for a fresh code from whichever method you set up.
Recovery codes
Right after you enable two-factor authentication, Tobren Operations generates 8
recovery codes and shows them to you once. Each looks like K7QF-9MNX-PR4T-H2WD.
You can’t move on until you’ve both copied and downloaded them — the app holds you on that screen until it’s sure you have a copy somewhere safe. Each code works exactly once; using one doesn’t consume the others.
There’s no way to view or regenerate your recovery codes later from the app. They’re shown exactly once, right after you set up (or reset) your second factor. Store them somewhere durable — a password manager, printed and filed — the same way you’d store any other one-time credential.
Getting back in if you lose your device
If you lose your authenticator app or your phone, use Recover your account from the sign-in screen. There are two ways in:
- Recovery code — enter one of the 8 codes you saved at enrollment.
- Email recovery — Tobren Operations emails a one-time code to your account’s address. It expires in 15 minutes.
Either path does the same thing, and it’s worth understanding exactly what: it removes the second factor from your account and nothing else. It does not sign you in, and it does not touch or reveal your password. You still sign in normally with your email and password afterward, and — because you no longer have a second factor enrolled — you’re walked straight back into 2FA setup, where you’ll save a fresh set of 8 recovery codes.
Recovery attempts are rate-limited, so repeated wrong codes or OTP guesses lock out for a period rather than allowing unlimited tries.
Accepting a crew invite
If an admin invites you onto their roster, you’ll get an email with a link shaped
like /invite/pilot/<token>. That link is single-use and expires 7 days after
it’s sent — if it’s gone stale, ask whoever invited you to send a new one.
Opening the link:
- If you’re not signed in, you’re sent to sign in (or create an account) first, then brought straight back to finish accepting.
- Once you’re signed in, the invite links your account to the pilot record the admin already created for you — you’re on the roster the moment your invite was sent; accepting is what connects it to your own login.
- You land on a confirmation screen and then your workspace, where you can see your flights, currency status, and assignments.
If the link has already been used or has expired, the page tells you plainly which one happened and gives you a way out — either sign out (if you’re signed in as the wrong account) or go to your workspace if you already have access another way.
What’s next
- Who can do what once you’re in → Crew & roles
- What your Part 107 currency status means → Part 107 currency