What is Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) is an additional security layer used on the TPT platform to protect user accounts by requiring more than one verification factor during authentication or sensitive actions. MFA helps ensure that access to an account is granted only to the account owner, even if login credentials are compromised. MFA reduces the risk of unauthorized access to user accounts. It helps protect sensitive account data and critical actions even if a password is compromised.
Setting up your MFA
- If you choose to set up MFA when prompted, click Set Up MFA and select an Authenticator app. Setting up your MFA is completely optional.
- Select an Authenticator App.
- Scan the QR code.
- Your account will be added to the app and a six-digit code will appear. Enter this code and click Enable MFA.
- Once MFA is enabled, recovery codes are displayed.
- These codes are shown only once, so make sure to copy or download them and store them in a secure place. After confirming that the codes are saved, finish the setup.
- You can then open your user profile, go to the Manage MFA tab, and see your active MFA method along with recovery codes as a backup option.
- If you didn't save your recovery codes during setup, you can regenerate them later. It's recommended to save the recovery codes immediately and download the TXT file. Remember, each recovery code can be used only once.
Utilizing MFA
In certain instances, for example, after logging out and logging back in, the system will request MFA.
- Enter the code from your Authenticator app to access your account.
- You can also log in using recovery codes.
- When prompted to do the MFA, click Try Another Way on the bottom, and select Recovery Codes. Enter one of your saved recovery codes, click Verify, and you'll be redirected to your dashboard.
- If you can't log in using MFA or recovery codes, select the Lost Access to Your MFA option.
- You'll be guided through identity verification using KYC to restore access.
Managing your MFA
- Open your user profile and go to the Manage MFA tab.
- You are allowed to have a maximum of 10 MFA methods.
- When the first MFA method is added to the account, it is automatically set as the primary MFA method. The star icon indicates the primary MFA method, which can be changed at any time.
- You can rename an MFA method if needed by clicking the pencil icon on the right side of the MFA.
- To add a method: Click the +Add Another Method button under the list of existing MFAs
- To remove a method: Hover over the undesired method, and click the red trash can icon on the right side.
Where MFA Is Used on the TPT Platform
MFA is required when performing sensitive or critical actions on the platform, including:
- Login (after password verification)
- Withdrawals (confirming access to funds)
- Accessing the Document Hub (viewing or downloading sensitive documents)
- Accessing the Manage MFA page
- Removing an MFA method
For security reasons, MFA may be requested again when performing a critical action. If more than 10 minutes have passed since the last successful MFA verification, you will be asked to confirm MFA again when attempting a critical action, even if you are still logged in. This helps ensure that sensitive actions are always protected by recent verification.