Authenticator security and recovery
Protect account access with encrypted TOTP enrollment and one-use recovery codes.
Enrollment
Sign in with verified email, confirm your password, then add the displayed secret or provisioning URI to your authenticator. Confirm a current six-digit code before activation. Save the eight recovery codes offline; they are displayed only once.
Replay and session policy
Used time steps and recovery codes cannot be reused. Activating or disabling MFA revokes other sessions. Staff operations require a strong MFA session in production; the public demo does not require an account.
Operator responsibility
The MFA encryption key stays beside the private database with restrictive permissions. Back it up securely. Losing it must not silently reset enrolled users. Federated SSO and organizational identity provisioning remain separate provider integrations—not implied by this TOTP implementation.