Multi-factor authentication (MFA)
Add an authenticator app as a second sign-in step, remove a factor, and what to do when you are locked out without your phone.
Last reviewed October 11, 2026
Multi-factor authentication (MFA) adds a second step to your sign-in: a 6-digit code from an authenticator app on your phone. Even someone with your password cannot get in without it. This page is for anyone turning MFA on, off, or recovering from a lost phone.
What this page helps you do
- Enroll an authenticator app as a factor.
- Sign in with a code.
- Remove a factor.
- Get back in when you cannot produce a code.
You'll start from Settings > My Account > Multi-Factor Authentication.
Before you start
- Install an authenticator app on your phone. Any TOTP app works: 1Password, Bitwarden, Authy, Google Authenticator, Microsoft Authenticator.
- Your email must be verified. If it is not, the card shows Please verify your email to enable MFA with a Send Verification Link button.
- MFA is a personal setting; it protects your sign-in in every team.
Enroll a factor
- Open your profile menu at the bottom of the sidebar and choose Settings. On My Account, scroll to Multi-Factor Authentication.
- Click Setup a new Factor.
- Give the factor a name ("A memorable name to identify this factor", for example your phone's name) and click Set factor name.
- Scan the QR code with your authenticator app.
- Type the 6-digit code the app shows and click Enable Factor.
Helpful details
- Key areas: the factors table lists Factor Name, Type and Status.
- What you can do: enroll more than one factor, for example a second phone, by repeating the steps. Each one works on its own at sign-in.
- Good to know: only a QR code is shown; there is no text key to copy. There are no recovery codes either, so a second factor is your backup.
Sign in with a code
After your email and password (or Google or Discord), Boardssey shows Verify your account. Type the current code from your app and click Submit Verification Code.
Helpful details
- Key areas: with more than one factor enrolled, you first pick one under "Choose a factor to verify your identity".
- What you can do: wait for the next code if one is refused; codes change every 30 seconds.
- Good to know: the check applies to every sign-in method once a factor is enrolled, Google and Discord included.
Remove a factor
In the factors table, click the unenroll action at the end of the factor's row. In the Unenroll Factor dialog, click Yes, unenroll factor.
Helpful details
- Key areas: the Multi-Factor Authentication card.
- What you can do: remove an old phone's factor after enrolling the new one.
- Good to know: removing your last factor turns MFA off. We recommend keeping it on, especially for Admins and the Primary Owner.
Locked out without your phone
If you cannot produce a code, the sign-in stops at the Verify your account screen.
- If you enrolled a second factor, pick it under "Choose a factor to verify your identity" and use that app.
- If your phone's clock is wrong, turn on automatic time and try the code again.
- Otherwise click Sign out at the bottom of the screen to leave it, and contact us through the chat bubble on boardssey.com from the email on your account. We will check your identity before we reset MFA.
Helpful details
- Key areas: the Sign out link on the code screen.
- What you can do: once you are back in, enroll a factor on your current phone right away.
- Good to know: there are no recovery codes and no SMS fallback. Teammates and Admins cannot reset your MFA; only Boardssey support can, after verifying you.
Tips & common questions
Which authenticator app should I use? Any TOTP app. Pick one that backs up or syncs across devices, so a lost phone does not lock you out.
Can I use MFA on two devices? Yes. Enroll a second factor from the second device, or use an app that syncs.
I enrolled MFA and now Google sign-in asks for a code too. That is expected. The code screen follows every sign-in method once a factor exists.
Can I require MFA for my whole team? Not today. MFA is per person.
Why did a code fail? It expired while you typed, or your phone's clock is off. Wait for a fresh code and turn on automatic time.