Appearance
Multi-Factor Authentication (MFA)
Multi-Factor Authentication adds an extra layer of security to your VeriPrompt account. When enabled, you need both your password and a time-based code from your authenticator app to sign in.
Why enable MFA?
- Protects your account even if your password is compromised
- Required by many compliance frameworks (SOC 2, HIPAA, GDPR best practices)
- Takes less than 2 minutes to set up
Supported authenticator apps
VeriPrompt uses TOTP (Time-based One-Time Password), which works with any standard authenticator app:
| App | Platform | Notes |
|---|---|---|
| Google Authenticator | iOS, Android | Simple, widely used |
| Microsoft Authenticator | iOS, Android | Good for Microsoft ecosystem users |
| Authy | iOS, Android, Desktop | Multi-device sync, cloud backup |
| 1Password | All platforms | Built into password manager |
| Bitwarden | All platforms | Open-source, built into password manager |
Enable MFA
Step 1: Open your profile
- Sign in to VeriPrompt
- Click your avatar or name in the top-right corner
- Select Profile
Step 2: Start 2FA setup
- Scroll to the Two-Factor Authentication section
- Click Enable 2FA
Step 3: Scan the QR code
- Open your authenticator app on your phone
- Tap the + (add) button in your app
- Select Scan QR code
- Point your camera at the QR code displayed on screen
Can't scan the QR code?
Click the manual entry key shown below the QR code and type it into your authenticator app. You can also copy it to your clipboard.
Step 4: Verify setup
- Your authenticator app now shows a 6-digit code that refreshes every 30 seconds
- Enter the current 6-digit code in the verification field
- Click Verify & Enable
Your MFA is now active. You will be asked for a code each time you sign in.
Sign in with MFA
Once MFA is enabled, the sign-in flow becomes:
- Enter your email and password as usual
- You are redirected to the Two-Factor Authentication page
- Open your authenticator app and enter the current 6-digit code
- Click Verify (or the code auto-submits when you type all 6 digits)
Session timer
The MFA challenge page shows a 5-minute countdown. If the timer expires, you will need to sign in again with your password. This is a security measure to prevent stale authentication sessions.
What if the code is wrong?
- Double-check you are reading the code for VeriPrompt in your authenticator app
- Codes refresh every 30 seconds — if the code is about to expire, wait for the next one
- You have 5 attempts before the session is invalidated and you must start over
- Make sure your phone's clock is synchronized (TOTP depends on accurate time)
Disable MFA
If you need to disable MFA (for example, before switching phones):
- Go to Profile → Two-Factor Authentication
- Click Disable 2FA
- Enter your current password and a current authenticator code
- Click Disable 2FA to confirm
WARNING
Disabling MFA removes the second factor from your account. If your company requires MFA, you may be asked to re-enable it.
Switching devices
If you are switching to a new phone:
- Before wiping or resetting your old phone, disable MFA in VeriPrompt
- Set up MFA again on your new phone using the steps above
- Verify the new device works before decommissioning the old one
Planning ahead
Some authenticator apps (like Authy and 1Password) support multi-device sync or cloud backup. If you use one of these, your TOTP codes transfer automatically when you set up your new device.
Troubleshooting
"Invalid MFA code" error
| Cause | Fix |
|---|---|
| Code expired | Wait for the next 30-second code and try again |
| Wrong account | Make sure you are reading the code labeled "Veriprompt" |
| Clock drift | Sync your phone's clock: Settings → Date & Time → Set Automatically |
| Too many attempts | Start over — sign in again with your password |
"MFA session expired"
The 5-minute window has passed. Click Back to Sign In and enter your password again.
Locked out (lost authenticator)
If you have lost access to your authenticator app and cannot generate codes:
- Contact your company administrator — they can disable MFA on your account from the admin panel
- If you are a solo account owner, contact VeriPrompt support
Security best practices
- Enable MFA on all accounts, especially admin and owner accounts
- Back up your authenticator — use an app with cloud sync (Authy, 1Password, Bitwarden) or save recovery codes
- Never share your authenticator codes or secret key with anyone
- Use a dedicated authenticator app rather than SMS-based codes (which are vulnerable to SIM-swapping attacks)
Next steps
- Account Management — Manage your profile and settings
- Security & Compliance FAQ — Learn about VeriPrompt's security measures
- Authentication — API key management and session tokens
