Multi-factor authentication (MFA) adds an extra layer of security to your account. Even if someone learns your password, they can't access your account without the second factor.
MFA Methods Available
Zenovay supports two MFA methods:
| Method | Security Level | Convenience | Best For |
|---|---|---|---|
| Authenticator App (TOTP) | High | Medium | Most users |
| Security Keys (WebAuthn) | Highest | Medium | Security-conscious users |
Recommended
We recommend authenticator apps for the best balance of security and convenience.
Setting Up Authenticator App (TOTP)
TOTP (Time-based One-Time Password) uses an authenticator app to generate codes.
Supported Authenticator Apps
- Google Authenticator (iOS, Android)
- Authy (iOS, Android, Desktop)
- 1Password (All platforms)
- Microsoft Authenticator (iOS, Android)
- Bitwarden (All platforms)
Setup Steps
Go to Security Settings
Navigate to Settings → Security in your dashboard.
Enable MFA
Click Enable Multi-Factor Authentication.
Choose Authenticator App
Select Authenticator App as your method.
Scan QR Code
Open your authenticator app and scan the QR code displayed. Alternatively, enter the secret key manually.
Enter Verification Code
Type the 6-digit code from your authenticator app to verify setup.
Save Backup Codes
Download or write down your backup codes. Store them securely.
Save your backup codes immediately! They're the only way to recover your account if you lose access to your authenticator.
Setting Up Security Keys (WebAuthn)
Pro PlanSecurity keys provide the strongest protection against phishing.
Supported Security Keys
- YubiKey (all models)
- Google Titan
- Thetis
- Feitian
- Built-in platform authenticators (Touch ID, Windows Hello)
Go to Security Settings
Navigate to Settings → Security.
Enable MFA
Click Enable Multi-Factor Authentication.
Choose Security Key
Select Security Key as your method.
Insert Security Key
Insert your security key into a USB port or have NFC ready.
Touch Security Key
When prompted, touch the button on your security key.
Name Your Key
Give your key a recognizable name (e.g., "Office YubiKey").
Add Backup Method
Add a backup method (another key or authenticator app) for recovery.
Using MFA When Logging In
After enabling MFA:
- Enter your email and password as usual
- When prompted for your second factor:
- Authenticator: Enter the 6-digit code
- Security Key: Insert and touch your key
- Optionally check "Remember this device" on trusted computers
Managing MFA Settings
Viewing Enabled Methods
- Go to Settings → Security
- See all enabled MFA methods
- View when each was added
Changing Methods
To switch MFA methods:
- Add the new method first
- Verify it works by logging out and back in
- Remove the old method if desired
Disabling MFA
Disabling MFA reduces your account security. Only do this if absolutely necessary.
- Go to Settings → Security
- Click Disable MFA
- Confirm with your current MFA code
- Enter your password to confirm
Backup Codes
Backup codes let you access your account if you lose your MFA device.
About Backup Codes
- 10 single-use codes generated
- Each code can only be used once
- Codes don't expire unless regenerated
- Store them securely (password manager, safe, etc.)
Using a Backup Code
- On the MFA prompt, click Use backup code
- Enter one of your backup codes
- You'll be logged in (that code is now invalid)
Regenerating Backup Codes
If you've used codes or lost them:
- Log in to your account
- Go to Settings → Security
- Click Regenerate Backup Codes
- Confirm with your current MFA code
- Save the new codes (old ones become invalid)
Troubleshooting
Authenticator Code Not Working
- Ensure your device time is correct (sync automatically)
- Make sure you're using codes for Zenovay, not another service
- Try the next code (they refresh every 30 seconds)
- Use a backup code if issues persist
Lost Authenticator App
- Use a backup code to log in
- Disable the old MFA method
- Set up MFA again with a new device
Security Key Not Recognized
- Try a different USB port
- Update browser (Chrome recommended)
- Check key is WebAuthn compatible
- Try the key on another computer
Enterprise MFA
Enterprise PlanEnterprise accounts have additional MFA options:
- Mandatory MFA: Require MFA for all team members
- Approved Methods: Limit which MFA methods are allowed
- SSO Integration: Use your identity provider's MFA
- Audit Logging: Track all MFA events
Best Practices
- Use authenticator apps for the best balance of security and convenience
- Register multiple methods as backup (e.g., TOTP app and a security key)
- Store backup codes securely (encrypted password manager)
- Enable MFA on your email too
- Keep authenticator app backed up (Authy supports this)