Skip to content

Authenticator app (TOTP)

Multi-factor authentication (MFA) adds a second step to sign-in: after your password, you enter a short-lived six-digit code from an authenticator app. This means a stolen password alone is not enough to get into your account. This page shows how to enrol an authenticator app.

  1. Open your user profile from Users in the sidebar (or your account menu) and go to Security Settings.
  2. Under the authenticator section, start enrolment. DASH displays a QR code and the equivalent provisioning URI.
Screenshot pendingThe QR code and provisioning URI shown when you enrol an authenticator
  1. In your authenticator app, add a new account by scanning the QR code. If you cannot scan, enter the provisioning URI manually instead.
  2. Your app now shows a rotating six-digit code for DASH.
  3. Enter the current code back in DASH to confirm enrolment. An incorrect code is rejected and enrolment does not complete — wait for the next code and try again.

On successful enrolment, DASH displays eight single-use backup codes, formatted like xxxx-xxxx.

  1. Print or save them now — they are shown only once and cannot be retrieved later.
  2. Store them somewhere safe and separate from your phone.

These codes let you sign in if you ever lose access to your authenticator. See Backup codes.

Once enrolled, your password alone will not sign you in:

  1. Enter your email and password as usual.
  2. DASH presents an MFA challenge. Enter the current six-digit code from your app.
  3. On success you reach the dashboard (or the account picker if you belong to several accounts).

A code cannot be reused for a second sign-in, and a challenge expires five minutes after it is issued. Too many wrong codes returns you to the Login screen to start over.

Security Settings shows whether the authenticator is Enabled or Not Enabled, along with how many backup codes remain. You can remove the authenticator from there; removing it turns off the MFA gate for your sign-in and clears any unused backup codes.