Beta Crew2FA is currently in beta — features may change and you may encounter bugs. Please report issues to bug_report@crew2fa.com. Learn more

Free Shared 2FA Authenticator codes for Teams

Crew2FA lets your organization store and share TOTP secrets securely with your team for FREE. Every admin and member signs in with their own authenticator -- no shared passwords -- and again it is FREE to use!

Multi-tenant

Each organization is fully isolated. Users can belong to many orgs with different roles.

Strong 2FA

Login requires a password plus a TOTP code from Google Authenticator, Apple Passwords, or any RFC 6238 client.

Encrypted at rest

Every TOTP secret is encrypted with Fernet (AES-128 + HMAC). Backed up by recovery codes if a device is lost.

How it works

  1. Create your organization
    One email, one password, one organization. Takes about a minute.
    Sign up
  2. Enable your own 2FA
    Scan the QR with Google Authenticator, Apple Passwords, 1Password, Bitwarden — any RFC 6238 client works.
    Read the guide
  3. Add the codes you want to share
    Stripe, AWS, GitHub — anything with a TOTP secret. Invite teammates by email; they redeem a one-time code.
    Add a site

Who is it for?

Marketing teams

Agency owners sharing client logins for Meta, Google Ads, Klaviyo, and HubSpot — without texting 6-digit codes back and forth.

Managed service providers

MSPs handling 2FA for client infrastructure — AWS, Azure, hosting panels, cPanel, Plesk. Each client org stays fully isolated.

IT consultants

Solo or small-firm consultants covering on-call rotation for shared infrastructure accounts. Invite a backup admin without giving them your phone.

Small dev teams

Shared GitHub org, NPM publish tokens, Docker Hub, Cloudflare — code that ships from CI needs the same TOTP the on-call engineer uses.

E-commerce stores

Store owner and bookkeeper sharing Shopify, WooCommerce, or Stripe 2FA without exposing either person's authenticator.

Nonprofits

Small volunteer teams sharing donor-management, email, or hosting logins. No IT department, no shared phone, no shared password.

Read the full walkthrough · How we keep it secure

A dashboard built for sharing

Every TOTP code for every organization you belong to — grouped by org, ready to copy, rotated every 30 seconds. No shared phones, no shared passwords.

Crew2FA dashboard showing shared TOTP codes for Stripe, GitHub, AWS, Cloudflare, Google, and Slack, grouped under the Acme organization

Security first

  • Encrypted at rest. Every TOTP secret is wrapped with Fernet (AES-128 + HMAC) before it touches the database.
  • Strong password hashing. Argon2id with a per-user salt. Login requires both the password and a current TOTP code.
  • Multi-tenant isolation. Every query keys on organization_id — no shared schemas, no leaked cross-org data.
  • Audit log on every mutation. Signup, invite, site add, password change, login failures. Read the security details.

Frequently asked questions

Is there a free tier?

Yes — the entire service is free. We keep the lights on with unobtrusive advertising on public pages only. Read the full pricing story.

Can I use Crew2FA with my existing authenticator app?

Yes. We speak RFC 6238 — Google Authenticator, Apple Passwords, 1Password, Bitwarden, Authy, and any other TOTP client work without changes.

What happens if my phone breaks?

Every account gets 10 single-use recovery codes at enrollment. Use one to sign in and mint a fresh batch. If you lose both, an admin can reset your account from the operator CLI.

Is there a team-size limit?

No. Orgs of 2 and orgs of 200 share the same price — free.

How invites work
  1. An admin adds a new member by email and picks a role.
  2. The system generates a one-time numeric code tied to that membership.
  3. The admin shares the code out-of-band.
  4. The recipient redeems it — creating a new account, or linking an existing one.
Free, ad-supported

This service is free. We keep the lights on with unobtrusive advertising on public pages. Authenticated pages are kept clean so you can focus.

Ready to share 2FA codes across your team?

Free. Ad-supported on public pages. Zero ads on authenticated pages.