> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://support.robaws.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How multi-factor authentication works

Multi-factor authentication (MFA) is an extra layer of security when you log in to Robaws. On top of your [password](https://support.robaws.com/en/article/changing-your-password-1ripat0/) you then also need a one-time code from an authenticator app on your mobile phone. That way nobody gets into your environment with a leaked password alone.

||| MFA only works if you log in with your username and password. If you log in with your Google or Microsoft account, the security that is set on that account applies.

## Enabling multi-factor authentication

You arrange MFA for your own account via your profile: click on your name at the top right, choose **profile** and go to the **multifactor authentication** card.

1. Click on **enable multifactor authentication**.
2. Scan the QR code with an authenticator app.
3. Enter the one-time access code that the app shows.
4. Click on **enable multifactor authentication**.
5. Note down your recovery codes and click on **I saved my recovery codes**.

![The multifactor authentication card on your profile](https://storage.crisp.chat/users/helpdesk/website/-/e/a/d/f/eadf6dec760ec000/en-5-1789034373847_1j04c8g.png)

From then on Robaws asks for the code from your authenticator app at every login.

| Use **Google Authenticator** or **Authy**: those are the apps that Robaws itself suggests on screen. Robaws uses SHA-256 as its hash algorithm instead of the usual SHA-1, and not every authenticator app can handle that. Does your app keep showing codes that Robaws refuses with 'The one-time access code is invalid', while the clock on your phone is correct? Then that is almost always the cause. In that case, choose one of the two apps above.

Cannot scan the QR code? The secret key that you enter manually in your app is shown underneath the code. Set the algorithm to **SHA-256** yourself, the code length to **6 digits** and the period to **30 seconds**.

## Logging in with MFA

1. Enter your username and password.
2. Robaws asks for the one-time access code. Get it from the authenticator app with which you enabled MFA.
3. Enter the code and click on **login**.

## Your recovery codes

When you enable MFA, you receive **ten recovery codes**. Keep them in a safe place, separate from your phone. You use a recovery code instead of the code from your app, for example when you lose your device.

||| Each recovery code works only once and then disappears from your list. If you lose both your device and your recovery codes, you can no longer log in and you cannot disable MFA yourself either. In that case, read [disabling multi-factor authentication](#2-disabling-multi-factor-authentication) and [problems logging in](https://support.robaws.com/en/article/problems-logging-in-1dneo4z/).

## Disabling multi-factor authentication

Go to your profile again and click on **disable multifactor authentication**. You then enter a valid code from your authenticator app, or one of your recovery codes.

Can you no longer enter either of them, for example because you have lost your phone and cannot find your recovery codes any more? Then you cannot disable MFA yourself. Contact [support@robaws.com](mailto:support@robaws.com) to look at the next steps.