What is 2FA?
Two-Factor Authentication (2FA) is a security method that requires two forms of verification to access an account or complete actions.
This code refreshes every 30 seconds. That means even if someone gains access to your account, they won’t be able to take sensitive actions without access to your phone.
2FA on Contra
To protect user accounts, we require 2FA at key checkpoints (like whenever you make a payout or change the email address on your account) to help prevent unauthorized access and activity.
You can manage your 2FA settings at any time by visiting your Security settings.
2FA flow
2FA setup is a 3 step process:
Click “Enable Two-Factor Authentication” here.
Scan the QR code or enter manually if scanning does not work
Setup your authenticator app on your device. Here are some options:
Built-in: iOS Passwords, Google Password Manager
Apps: Google Authenticator, Microsoft Authenticator, Authy
Password managers: 1Password, Bitwarden, LastPass, Dashlane
If you are having issues setting up 2FA, reach out to hello@contra.com for support.
Common 2FA setup issues
Issue | Resolution |
Can't scan QR code | Click "Can't scan? Enter manually" link below the QR code for a text-based setup key |
Code not working | Ensure phone time is synced automatically (Settings → Date & Time → Set Automatically). Codes are time-sensitive |
My codes are being rejected | It's possible you are using an old code. Clear all Contra items from your authenticator app and then request a new code. |
I can't withdraw funds without 2FA | We require 2FA to withdraw funds to keep your payouts safe and confirm it's really you making the withdrawal. Please enable 2FA and complete the steps to withdraw your funds. |
How to detect and report potential scams
Scams come in all shapes and sizes. When discussing a project with a potential client, don’t share personal payment information or agree to unusual requests (such as accepting funds to pay other freelancers).
Here are a few more red flags that may indicate suspicious or unsafe client behavior:
Requests for unpaid work: If a client asks you to complete work without a signed proposal or payment agreement, that is a red flag and against our Code of Conduct.
Application or start-up fees: Legitimate clients will never ask you to pay to apply or begin working.
Pushing to move off-platform: Clients insisting on taking the conversation off Contra before a proposal is signed may be attempting to bypass our safety checks.
Suspicious links or downloads: Be cautious if a client asks you to download software or click unfamiliar links, especially early in the conversation.
If anything feels off, trust your gut and contact us at hello@contra.com.
