Guide: MFA Getting Started

Enable TOTP-based MFA, store backup codes, and verify sign-in second-step behavior.

  1. Open /account and go to the security section.
  2. Select Enable MFA to generate QR + manual key.
  3. Scan in authenticator app, enter OTP code, and verify.
  4. Store backup codes offline; they are shown only once.
  5. On next sign-in, complete the MFA challenge before session issuance.