← Auth / Security

Two-factor authentication v2

auth / security · features

A second factor at login on top of the password — a one-time TOTP code from an authenticator app. A user enables MFA from the "Security" card in their profile; entry to setup is protected by re-entering the password. A three-step wizard connects the second factor, after which two-factor authentication is active and managed on the same screen.

Flow
Profile / Account shared · entry · "Security" card
"Set up" · sudo-protected
Re-auth modal shared · password re-entry
password confirmed
MFA Setup start · 3-step wizard
codes saved · MFA active
MFA Management management · regeneration · disabling