Skip to content

Multi-Factor Authentication (MFA) ​

Multi-Factor Authentication adds an extra layer of security to your VeriPrompt account. When enabled, you need both your password and a time-based code from your authenticator app to sign in.

Why enable MFA? ​

  • Protects your account even if your password is compromised
  • Required by many compliance frameworks (SOC 2, HIPAA, GDPR best practices)
  • Takes less than 2 minutes to set up

Supported authenticator apps ​

VeriPrompt uses TOTP (Time-based One-Time Password), which works with any standard authenticator app:

AppPlatformNotes
Google AuthenticatoriOS, AndroidSimple, widely used
Microsoft AuthenticatoriOS, AndroidGood for Microsoft ecosystem users
AuthyiOS, Android, DesktopMulti-device sync, cloud backup
1PasswordAll platformsBuilt into password manager
BitwardenAll platformsOpen-source, built into password manager

Enable MFA ​

Step 1: Open your profile ​

  1. Sign in to VeriPrompt
  2. Click your avatar or name in the top-right corner
  3. Select Profile

Step 2: Start 2FA setup ​

  1. Scroll to the Two-Factor Authentication section
  2. Click Enable 2FA

Step 3: Scan the QR code ​

  1. Open your authenticator app on your phone
  2. Tap the + (add) button in your app
  3. Select Scan QR code
  4. Point your camera at the QR code displayed on screen

Can't scan the QR code?

Click the manual entry key shown below the QR code and type it into your authenticator app. You can also copy it to your clipboard.

Step 4: Verify setup ​

  1. Your authenticator app now shows a 6-digit code that refreshes every 30 seconds
  2. Enter the current 6-digit code in the verification field
  3. Click Verify & Enable

Your MFA is now active. You will be asked for a code each time you sign in.

Sign in with MFA ​

Once MFA is enabled, the sign-in flow becomes:

  1. Enter your email and password as usual
  2. You are redirected to the Two-Factor Authentication page
  3. Open your authenticator app and enter the current 6-digit code
  4. Click Verify (or the code auto-submits when you type all 6 digits)

Session timer

The MFA challenge page shows a 5-minute countdown. If the timer expires, you will need to sign in again with your password. This is a security measure to prevent stale authentication sessions.

What if the code is wrong? ​

  • Double-check you are reading the code for VeriPrompt in your authenticator app
  • Codes refresh every 30 seconds — if the code is about to expire, wait for the next one
  • You have 5 attempts before the session is invalidated and you must start over
  • Make sure your phone's clock is synchronized (TOTP depends on accurate time)

Disable MFA ​

If you need to disable MFA (for example, before switching phones):

  1. Go to Profile → Two-Factor Authentication
  2. Click Disable 2FA
  3. Enter your current password and a current authenticator code
  4. Click Disable 2FA to confirm

WARNING

Disabling MFA removes the second factor from your account. If your company requires MFA, you may be asked to re-enable it.

Switching devices ​

If you are switching to a new phone:

  1. Before wiping or resetting your old phone, disable MFA in VeriPrompt
  2. Set up MFA again on your new phone using the steps above
  3. Verify the new device works before decommissioning the old one

Planning ahead

Some authenticator apps (like Authy and 1Password) support multi-device sync or cloud backup. If you use one of these, your TOTP codes transfer automatically when you set up your new device.

Troubleshooting ​

"Invalid MFA code" error ​

CauseFix
Code expiredWait for the next 30-second code and try again
Wrong accountMake sure you are reading the code labeled "Veriprompt"
Clock driftSync your phone's clock: Settings → Date & Time → Set Automatically
Too many attemptsStart over — sign in again with your password

"MFA session expired" ​

The 5-minute window has passed. Click Back to Sign In and enter your password again.

Locked out (lost authenticator) ​

If you have lost access to your authenticator app and cannot generate codes:

  1. Contact your company administrator — they can disable MFA on your account from the admin panel
  2. If you are a solo account owner, contact VeriPrompt support

Security best practices ​

  • Enable MFA on all accounts, especially admin and owner accounts
  • Back up your authenticator — use an app with cloud sync (Authy, 1Password, Bitwarden) or save recovery codes
  • Never share your authenticator codes or secret key with anyone
  • Use a dedicated authenticator app rather than SMS-based codes (which are vulnerable to SIM-swapping attacks)

Next steps ​