Skip to main content
Documentation

Multi-Factor Authentication

Multi-factor authentication (MFA) protects your Nexigon account by requiring a code from an authenticator app as well as your password. Nexigon uses time-based one-time passwords (TOTP): six-digit codes that change every 30 seconds. Recovery codes are single-use substitutes for app codes and still require your password. MFA protects your account across all its organizations. Your Hub operator can require instance administrators, organization administrators, or both to set up MFA before using Nexigon. If you hold both roles, either requirement applies.

Set Up an Authenticator

  1. Open User Settings β†’ Security and select Set up authenticator app.
  2. Verify your password if prompted, then scan the QR code with your authenticator app. You can also enter the setup key manually.
  3. Enter the current code from the app and select Confirm authenticator.
  4. Copy or download the ten recovery codes and store them somewhere safe. Select I saved my recovery codes to finish.

Sign In

After entering your email and password, enter the code from your authenticator app. If you have already used a code, wait for the app to show a new one. Select Use a recovery code when you cannot access your authenticator.

Replace an Authenticator or Recovery Codes

In User Settings β†’ Security, select Replace authenticator. If prompted, verify with your password and an authenticator or unused recovery code. Complete setup with the new app and save the new recovery codes. After signing in with a recovery code, replace a lost authenticator immediately. That sign-in lets you complete one replacement without spending another code, even if you used your last one. Setup expires after a few minutes; closing it does not extend the time limit, but you can reopen it in the same browser tab before it expires, including after a page reload.

Select Regenerate recovery codes to replace the codes without replacing your authenticator. Confirm that your previous codes will stop working, then verify your password and an authenticator or unused recovery code. Save the new set.

Select Disable MFA to remove the second-factor requirement. Confirm that your account will rely on its password alone, then verify your credentials. This option is unavailable when your administrator account is required to keep MFA enabled.

Credential and Session Rules

MFA becomes active when the authenticator is confirmed. A replacement leaves the old authenticator active until confirmation. Enrollment, replacement, and removal sign out other sessions. Password changes sign out all sessions and preserve the account’s MFA settings. Manage MFA in the Nexigon web interface; the public API and SDKs do not expose MFA settings. API tokens retain their existing permissions. When administrators are required to use MFA, their existing sessions and user API tokens are blocked until setup is complete.

MFA changes ask you to verify your credentials for the change you selected. That verification permits only that change and leaves your current sign-in unchanged. Other security changes and token creation may ask you to verify again if some time has passed. That general verification replaces your session credential, so copies of the previous credential stop working. Neither type of verification extends your sign-in lifetime.

Recovery codes are shown only when generated. Regenerating them or confirming a replacement authenticator invalidates every previous code. If both the authenticator and all recovery codes are lost, resetting the password does not remove MFA, and email alone cannot recover access.