Skip to main content

Platform safety

A guide to two-factor authentication on your Contra account.

Isabel avatar
Written by Isabel
Updated today

What is 2FA?

Two-Factor Authentication (2FA) is a security method that requires two forms of verification to access an account or complete actions.

This code refreshes every 30 seconds. That means even if someone gains access to your account, they won’t be able to take sensitive actions without access to your phone.

2FA on Contra

To protect user accounts, we require 2FA at key checkpoints (like whenever you make a payout or change the email address on your account) to help prevent unauthorized access and activity.

You can manage your 2FA settings at any time by visiting your Security settings.

2FA flow

2FA setup is a 3 step process:

  1. Click “Enable Two-Factor Authentication” here.

  2. Scan the QR code or enter manually if scanning does not work

  3. Setup your authenticator app on your device. Here are some options:

    • Built-in: iOS Passwords, Google Password Manager

    • Apps: Google Authenticator, Microsoft Authenticator, Authy

    • Password managers: 1Password, Bitwarden, LastPass, Dashlane

If you are having issues setting up 2FA, reach out to hello@contra.com for support.

Common 2FA setup issues

Issue

Resolution

Can't scan QR code

Click "Can't scan? Enter manually" link below the QR code for a text-based setup key

Code not working

Ensure phone time is synced automatically (Settings → Date & Time → Set Automatically). Codes are time-sensitive

My codes are being rejected

It's possible you are using an old code. Clear all Contra items from your authenticator app and then request a new code.

I can't withdraw funds without 2FA

We require 2FA to withdraw funds to keep your payouts safe and confirm it's really you making the withdrawal. Please enable 2FA and complete the steps to withdraw your funds.

How to detect and report potential scams

Scams come in all shapes and sizes. When discussing a project with a potential client, don’t share personal payment information or agree to unusual requests (such as accepting funds to pay other freelancers).

Here are a few more red flags that may indicate suspicious or unsafe client behavior:

  • Requests for unpaid work: If a client asks you to complete work without a signed proposal or payment agreement, that is a red flag and against our Code of Conduct.

  • Application or start-up fees: Legitimate clients will never ask you to pay to apply or begin working.

  • Pushing to move off-platform: Clients insisting on taking the conversation off Contra before a proposal is signed may be attempting to bypass our safety checks.

  • Suspicious links or downloads: Be cautious if a client asks you to download software or click unfamiliar links, especially early in the conversation.

If anything feels off, trust your gut and contact us at hello@contra.com.

Did this answer your question?