How to Manage Multi-factor Authentication

In today’s digital world, security is a top priority for online platforms. Multi-factor authentication (MFA) adds more protection beyond your standard password. With MFA, an additional verification step ensures that only authorized users can access your account, even if your password is compromised. This helps safeguard your data and prevent unauthorized access. This guide will walk you through the steps to set up MFA for your Servebolt account.

Enabling MFA

Strengthen your Servebolt account security by requiring a second form of authentication during login. Follow the steps below to set up Multi-factor Authentication and enhance your security:

  1. Log into your Servebolt Account.
  2. Navigate to Security & Passwords.
  3. Under Multi-factor Authentication, click Enable:
    • A new window will open, where you must scan the QR code using your preferred authenticator app.
    • If you’re having trouble scanning the QR code, click “Trouble Scanning?” to manually enter the code into your authenticator app.
  4. Enter the one-time code and click “Continue“.
  5. Very important! Save the recovery code somewhere safe, as it is needed in case you lose access to the authenticated device or need to verify your identity.
  6. Done!

Servebolt API Usage

When MFA is enabled, the “Login” endpoint requires you to complete an OTP challenge, which is achieved by using the “MFA Challenge (OTP)” endpoint to get a usable access token.

Now that you have successfully enabled MFA, you will be asked for a one-time code every time you log in. You can choose to “Remember this device for 30 days” if you’re logging in from a trusted device.

Disabling MFA

Disabling the Multi-factor Authentication is done in a very similar way to enabling it. Follow these simple steps to disable:

Image from the Admin Panel showing where to disable Multi-factor Authentication.
  1. Go to Security & Passwords in your Account Settings.
  2. Click “Disable” in the MFA section.
  3. Log into your Servebolt account in the pop-up window and enter the one-time code from your authenticator app.
  4. Done!

The Recovery Code

Your Recovery Code is a backup method for accessing your account if you can no longer access your authenticator app or need to verify your identity. You need it when you cannot provide a one-time code, so make sure you keep it somewhere safe.

How to Reset Your Recovery Code

If you have access to your account, you can generate a new code:

  1. Navigate to your account’s Security & Password page.
  2. Click “Reset Recovery Code“.
  3. Log in to your account and enter the one-time code from your authenticator in the pop-up window.
  4. Save the generated code in a secure location.
  5. Done!

What to Do If You’re Locked Out

If you no longer have access to your authenticator app or the Recovery Code, you won’t be able to reset MFA on your own. Please contact us for assistance in verifying your identity and regaining access.