> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Multi-factor authentication

> Set up email, authenticator app, or passkey-based MFA.

Multi-factor authentication (MFA) adds a second verification step to sign-in, on top of your password. Scanova supports three methods — **email one-time codes**, an **authenticator app** (TOTP), and **passkeys** — and all three live inside a single **Manage MFA** drawer. You can enable more than one method, pick a default, and generate backup codes in case you lose access to your usual method.

<Note>
  MFA is only available for accounts that sign in with a password. If your organization signs in through [SSO](/authentication/sso), your identity provider handles authentication instead, and the MFA option doesn't appear in your account settings.
</Note>

## Opening Manage MFA

Go to **Account** (your avatar menu, or `/account`) and find the **Login & Security** section on the **Account** tab. The **Multi-Factor Authentication** field shows your current status (**Off**, or **On · \{method}**) with an edit icon that opens the drawer.

<Frame caption="The Login & Security section of Account settings, with Password and Multi-Factor Authentication fields">
  <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/account-page.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=6ac131f5ec11af7354db527d5f52f2da" alt="Scanova account page showing the Login and Security section with Password and Multi-Factor Authentication fields, the latter showing Off with an edit pencil icon" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/account-page.png" />
</Frame>

## Choosing a method

The first time you open the drawer, you're asked how you'd like to get your verification code:

<Frame caption="The Choose authentication method step, listing Email, Authenticator App, and Passkey">
  <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-drawer-status.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=22a7e08a89eaf241fa92da687aef26bb" alt="Choose authentication method drawer with three options: Email (receive a one-time code on your registered email), Authenticator App (use Google Authenticator or a similar TOTP app), and Passkey (use your device's fingerprint, face, or screen lock)" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-drawer-status.png" />
</Frame>

* **Email** — a one-time code is sent to your registered email address at sign-in.
* **Authenticator App** — codes are generated by an app like Google Authenticator (any TOTP-compatible app works).
* **Passkey** — your device's fingerprint, face unlock, or screen lock. See [Passkeys](/authentication/passkeys) for a dedicated walkthrough of this method.

<Tip>
  If your browser reports that your device supports a built-in (platform) authenticator, Passkey is listed first and flagged **Recommended for this device**.
</Tip>

Whichever method you pick, you're first asked to re-enter your password to confirm it's you:

<Frame caption="The password re-verification step before setting up a new MFA method">
  <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-drawer-password-reauth.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=f40bdc171ba1df033adf054a946d7aca" alt="Verify it's you step asking for your current password before setting up an authenticator app" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-drawer-password-reauth.png" />
</Frame>

<Note>
  If your account has no password (for example, you only ever signed in with Google), this step shows a **Continue with Google** button instead, so you can confirm your identity that way.
</Note>

## Setting up an authenticator app

<Steps>
  <Step title="Verify your password">
    Enter your current password and select **Next**.
  </Step>

  <Step title="Add the account to your authenticator app">
    Scan the QR code with an app like Google Authenticator, or select the manual-entry key if you can't scan.

    <Frame caption="The authenticator app setup step, with a scannable QR code and a manual-entry key">
      <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-drawer-authenticator-setup.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=b82d853dff5672ae621f7e49f4f3f40c" alt="Set up authenticator app step showing a QR code to scan, app store badges for Google Authenticator, and a manual entry key with a copy button" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-drawer-authenticator-setup.png" />
    </Frame>

    Select **Next** once the account appears in your app.
  </Step>

  <Step title="Enter the current code">
    Your authenticator app now shows a 6-digit code that refreshes periodically. Enter it and select **Verify**.

    <Frame caption="The verification code step after authenticator app setup">
      <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-drawer-verify.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=8e30adb385b1d0e53fea976306e697e9" alt="Enter verification code step with a six-digit one-time password input and a Verify button" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-drawer-verify.png" />
    </Frame>
  </Step>
</Steps>

<Check>
  On success you're shown your [backup codes](#saving-backup-codes) — the app is now an active MFA method on your account.
</Check>

## Email one-time codes

Choosing **Email** skips the app-setup step: after the password check, Scanova sends a 6-digit code to your registered email address and shows the same OTP-entry screen, with a countdown before you can request another code.

<Frame caption="The email one-time code entry step, showing a resend countdown">
  <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-email-verify-step.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=d3810b8c50a55e3e6b4b43eee1c97845" alt="Enter verification code step for email MFA, showing an OTP sent successfully toast, a six-digit code input, and a Resend OTP in 60s countdown" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-email-verify-step.png" />
</Frame>

## Passkeys

Passkeys use your device's built-in biometrics or screen lock instead of a code. Setup and sign-in both work a little differently from the code-based methods above — see [Passkeys](/authentication/passkeys) for the full walkthrough.

## Adding another method

Once you have at least one method enrolled, the drawer's main view lists it with a **Default** badge and a delete (trash) icon, and the footer button changes to **Add another method**:

<Frame caption="The MFA status view with one enrolled method">
  <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-drawer-status-one-method.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=eca27520d83eb1dc96b1ace7811a62f3" alt="Multi-factor Authentication drawer showing Passkey enrolled with a Default badge, a trash icon to remove it, and an Add another method button" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-drawer-status-one-method.png" />
</Frame>

Selecting **Add another method** re-opens the method picker — now only showing methods you haven't already enrolled, with copy adjusted to reflect that you already have MFA set up:

<Frame caption="Adding a second method once one is already enrolled">
  <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-add-another-method.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=6fc0dcc8c9eb9019e63c876e0df38bcd" alt="Choose authentication method step showing Email and Authenticator App options, with the intro text 'Add another sign-in method for extra resilience if you lose access to one'" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-add-another-method.png" />
</Frame>

If you enroll more than one method, each row gets a **Make default** button (unless it's already the default). Your default method is the one Scanova prompts for first at sign-in — you can still fall back to any other enrolled method or a backup code.

To remove a method, select its trash icon, confirm your password (or re-authenticate with Google), and it's removed immediately.

## Saving backup codes

After enrolling your first MFA method, Scanova generates a set of single-use recovery codes. Save them somewhere safe — each can be used once to sign in if you lose access to your regular MFA method, and they're never shown again after this step.

<Frame caption="The recovery codes step, with Download and Copy actions">
  <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-drawer-backup-codes.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=57530a92b8a9d4214b59ec58fa5b3e03" alt="Save your recovery codes step showing a grid of ten single-use backup codes, with Download and Copy buttons and a Done button" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-drawer-backup-codes.png" />
</Frame>

## Signing in with MFA

Once MFA is enabled, signing in with your password takes you to a security-check screen for your default method instead of straight into your account. For example, with a passkey as the default:

<Frame caption="The MFA security check at sign-in">
  <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-login-challenge.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=97096bf9b52a7ad4970068819c42175b" alt="Security check screen reading 'Use your passkey to finish signing in', with a Remember this device for 2 weeks checkbox, a Sign in with your passkey button, and a Use backup code link" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-login-challenge.png" />
</Frame>

Check **Remember this device for 2 weeks** to skip the MFA challenge on that browser for the next two weeks. If you can't use your default method, select **Use backup code** to enter one of the recovery codes you saved earlier:

<Frame caption="Signing in with a backup code instead of the default MFA method">
  <img src="https://mintcdn.com/scanova-api/2FTGGTqcp1qRUtvm/images/v2/authentication/multi-factor-authentication/mfa-login-backup-code-step.png?fit=max&auto=format&n=2FTGGTqcp1qRUtvm&q=85&s=945c2c126c0a72c6891c9def2f89aa4d" alt="Use backup code screen with a backup code input field, a Remember this device for 2 weeks checkbox, and a Verify button" width="1440" height="900" data-path="images/v2/authentication/multi-factor-authentication/mfa-login-backup-code-step.png" />
</Frame>

## Related

* [Passkeys](/authentication/passkeys) — a closer look at the passkey method.
* [Google login](/authentication/google-login) — how Google sign-in is used both for login and for re-confirming your identity on password-less accounts.
* [Password reset](/authentication/password-reset) — recovering access if you've forgotten your password (separate from MFA recovery codes).
