MFA Setup and Recovery
Multi-factor authentication (MFA) protects your account against password theft. This article covers enrollment in detail, explains backup codes, and walks through what to do if you lose your authenticator device.
How TOTP works
The portal uses TOTP (Time-based One-Time Passwords, RFC 6238). During enrollment, the portal and your authenticator app share a secret. Every 30 seconds both sides independently compute a six-digit code from that secret plus the current time. Because the code is time-derived, it is only valid for a brief window — an intercepted code is useless seconds later.
No network call is needed between your device and the portal to generate a code. If your authenticator app works in airplane mode, this is why.
Supported authenticator apps
Any TOTP-compatible app works. Commonly used options:
| App | Platforms | Notes |
|---|---|---|
| Authy | iOS, Android, Desktop | Cloud backup of secrets; useful if you change phones frequently |
| 1Password | iOS, Android, Mac, Windows | Combines password manager and TOTP in one app |
| Google Authenticator | iOS, Android | Simple; no cloud backup — export before switching devices |
| Microsoft Authenticator | iOS, Android | Cloud backup; supports both TOTP and push notifications |
| Bitwarden Authenticator | iOS, Android | Separate app from the Bitwarden password manager; open source |
Enrollment walkthrough
1. Open Account → Security
Sign in to the admin portal. From the top navigation select Account, then choose Security in the sidebar.
2. Enable authenticator app
Select Enable authenticator app. The portal generates a unique TOTP secret for your account and displays it as a QR code. The QR code is shown once — do not close this page until enrollment is complete.
3. Scan the QR code
In your authenticator app:
- Authy / Google Authenticator / Bitwarden: tap the
+icon → Scan QR code. - 1Password: open the item where you store your Serene Creations credentials → Edit → Add field → One-Time Password → camera icon.
- Microsoft Authenticator: tap
+→ Other account → scan.
Point your camera at the QR code on screen. The app adds an entry labelled “Serene Creations” (or similar) and immediately starts showing a six-digit rotating code.
4. Enter the confirmation code
In the portal, type the six-digit code currently shown in your authenticator app. If the code rotates while you are typing, enter the new one. Select Confirm.
5. Save your backup codes
After confirming, the portal displays 8 one-time backup codes. These are your recovery keys if you ever lose your authenticator device.
Treat backup codes like passwords:
- Copy them into your password manager under the Serene Creations entry.
- Do not screenshot them and leave the screenshot in your camera roll.
- Do not email them to yourself.
Each code can only be used once. When you use one, the portal marks it consumed. If you run low, generate a fresh set under Account → Security → Regenerate backup codes (this invalidates all unused old codes).
Signing in with MFA active
- Enter your email and passphrase on the sign-in screen.
- After password verification, the portal prompts for your MFA code.
- Open your authenticator app, copy the current six-digit code, and enter it.
- Select Verify. A new session is created and you are redirected to the portal home.
If the code is rejected:
- “Invalid code” — the code may have expired mid-entry. Wait for the next rotation (up to 30 seconds) and try again.
- “Device clock skew” — TOTP requires accurate time. Enable automatic time sync on your device (Settings → Date & Time → Set Automatically on iOS/Android).
Using a backup code
If your authenticator device is unavailable:
- On the MFA prompt screen, select Use a backup code.
- Enter one of your saved backup codes exactly as shown (hyphens included).
- You are signed in. The code you used is now invalidated.
- Immediately re-enroll a new authenticator device (see below) so you are not locked out again.
Replacing your authenticator app or device
If you are switching phones or want to move to a different app:
- Sign in to the portal using your current authenticator (or a backup code).
- Go to Account → Security.
- Select Remove authenticator app. This disables MFA temporarily.
- Select Enable authenticator app and follow the enrollment steps above with your new device.
- Save the new backup codes — the old ones are invalidated.
Disabling MFA
Disabling MFA is not recommended. If you need to disable it (for example, to move between apps and your backup codes are also unavailable), contact support with account verification details.
Next steps
- Session management — configure how long sessions stay active.
- Tenant Setup — continue onboarding after securing your account.