MFA Setup and Recovery

Multi-factor authentication (MFA) protects your account against password theft. This article covers enrollment in detail, explains backup codes, and walks through what to do if you lose your authenticator device.


How TOTP works

The portal uses TOTP (Time-based One-Time Passwords, RFC 6238). During enrollment, the portal and your authenticator app share a secret. Every 30 seconds both sides independently compute a six-digit code from that secret plus the current time. Because the code is time-derived, it is only valid for a brief window — an intercepted code is useless seconds later.

MFA sign-in flow — password entry, MFA prompt, authenticator code, access granted

No network call is needed between your device and the portal to generate a code. If your authenticator app works in airplane mode, this is why.


Supported authenticator apps

Any TOTP-compatible app works. Commonly used options:

App Platforms Notes
Authy iOS, Android, Desktop Cloud backup of secrets; useful if you change phones frequently
1Password iOS, Android, Mac, Windows Combines password manager and TOTP in one app
Google Authenticator iOS, Android Simple; no cloud backup — export before switching devices
Microsoft Authenticator iOS, Android Cloud backup; supports both TOTP and push notifications
Bitwarden Authenticator iOS, Android Separate app from the Bitwarden password manager; open source

Enrollment walkthrough

1. Open Account → Security

Sign in to the admin portal. From the top navigation select Account, then choose Security in the sidebar.

2. Enable authenticator app

Select Enable authenticator app. The portal generates a unique TOTP secret for your account and displays it as a QR code. The QR code is shown once — do not close this page until enrollment is complete.

3. Scan the QR code

In your authenticator app:

  • Authy / Google Authenticator / Bitwarden: tap the + icon → Scan QR code.
  • 1Password: open the item where you store your Serene Creations credentials → Edit → Add field → One-Time Password → camera icon.
  • Microsoft Authenticator: tap + → Other account → scan.

Point your camera at the QR code on screen. The app adds an entry labelled “Serene Creations” (or similar) and immediately starts showing a six-digit rotating code.

4. Enter the confirmation code

In the portal, type the six-digit code currently shown in your authenticator app. If the code rotates while you are typing, enter the new one. Select Confirm.

5. Save your backup codes

After confirming, the portal displays 8 one-time backup codes. These are your recovery keys if you ever lose your authenticator device.

Treat backup codes like passwords:

  • Copy them into your password manager under the Serene Creations entry.
  • Do not screenshot them and leave the screenshot in your camera roll.
  • Do not email them to yourself.

Each code can only be used once. When you use one, the portal marks it consumed. If you run low, generate a fresh set under Account → Security → Regenerate backup codes (this invalidates all unused old codes).


Signing in with MFA active

  1. Enter your email and passphrase on the sign-in screen.
  2. After password verification, the portal prompts for your MFA code.
  3. Open your authenticator app, copy the current six-digit code, and enter it.
  4. Select Verify. A new session is created and you are redirected to the portal home.

If the code is rejected:

  • “Invalid code” — the code may have expired mid-entry. Wait for the next rotation (up to 30 seconds) and try again.
  • “Device clock skew” — TOTP requires accurate time. Enable automatic time sync on your device (Settings → Date & Time → Set Automatically on iOS/Android).

Using a backup code

If your authenticator device is unavailable:

  1. On the MFA prompt screen, select Use a backup code.
  2. Enter one of your saved backup codes exactly as shown (hyphens included).
  3. You are signed in. The code you used is now invalidated.
  4. Immediately re-enroll a new authenticator device (see below) so you are not locked out again.

Replacing your authenticator app or device

If you are switching phones or want to move to a different app:

  1. Sign in to the portal using your current authenticator (or a backup code).
  2. Go to Account → Security.
  3. Select Remove authenticator app. This disables MFA temporarily.
  4. Select Enable authenticator app and follow the enrollment steps above with your new device.
  5. Save the new backup codes — the old ones are invalidated.

Disabling MFA

Disabling MFA is not recommended. If you need to disable it (for example, to move between apps and your backup codes are also unavailable), contact support with account verification details.


Next steps