2FA by Fax sends one-time passcodes to registered fax numbers instead of SMS, email, or push. No SIM swapping. No signal required. Just the reassuring hum of a machine that has never once been phished.
Median delivery: 11.4s · 99.99% line uptime · G3 + T.38 supported
Each user enrolls a verified fax number. We confirm the line with a test page and a handshake fingerprint stored against the account.
One POST generates a six-digit passcode and queues the transmission. Our gateway dials, negotiates, and confirms receipt page by page.
The user walks to the machine, collects the sheet, and types the code. Codes expire in five minutes, whether or not toner cooperates.
No SIM swapping, no SS7 interception, no carrier support rep talked into a port-out on a Tuesday.
Six-digit passcodes printed on paper, delivered to a physical location you already control access to.
Works when the internet doesn't. Copper holds up in outages, dead zones, and basement records rooms.
Healthcare, legal, government, and finance teams with strict retention and compliance requirements.
A REST endpoint, a webhook, and SDKs for six languages. Drop-in replacement for your SMS provider.
The hum of a fax machine, the power of the future. Because security never goes out of style.
Every regulated workplace we've met already has a fax number, a fax log, and a person who guards both. We simply put your authentication factor where the paper trail already lives.
Send a challenge, verify a code, and subscribe to transmission webhooks — delivered, busy, no answer, out of paper. Sandbox lines are free and print to a virtual tray.
curl https://api.2fabyfax.com/v1/challenges \ -H "Authorization: Bearer $FAX_KEY" \ -d user_id=usr_10482 \ -d fax_number=+13125550148 \ -d cover_page=corporate_navy { "id": "chg_8Xf2c", "status": "dialing", "expires_in": 300, "pages": 1 }
500 transmissions included
5,000 transmissions included
Volume rates and dedicated trunks
2FA by Fax was founded in a records room in 2019 on a simple observation: the most secure device in most offices is the one nobody has bothered to connect to the internet.
Spent eleven years running identity programs for regional hospital networks. Started 2FA by Fax after an audit found the fax log was the only tamper-evident record in the building.
Former telecom engineer who has personally debugged more T.38 handshakes than he cares to count. Owns nine fax machines, four of which still work.
Built HIPAA and SOC 2 programs at two health-tech companies. Translates between auditors, attorneys, and engineers without raising her voice.
Came up through enterprise support desks in insurance and logistics. Believes every escalation is really a question about paper, toner, or a busy signal.
The gateway receives an out-of-paper status from the receiving unit and fires a webhook so your app can offer a retry or a secondary line. Codes never expire early.
It's a different threat model. Fax delivery trades remote attack surface for physical access control — which is exactly the trade regulated offices with badge readers want to make.
No. Virtual fax endpoints and multifunction printers work fine. We do think the physical unit is more fun, and we will not be talked out of that position.
Median 11.4 seconds from API call to transmission-complete, plus however long it takes your colleague to walk down the hall.
Secure. Reliable. Fax-delivered. Start a sandbox line in about four minutes.