Two-Factor Authentication (2FA)
Two-factor authentication adds an extra layer of security by requiring a verification code sent to your email in addition to your password.
Overview
When 2FA is enabled:
- Login: After entering your password, you'll receive a 6-digit code via email
- Sensitive actions: Changing your password or deleting your account requires email verification
Enabling 2FA
- Go to Settings → Security
- Find the Two-Factor Authentication card
- Click Enable 2FA
- Enter the 6-digit code sent to your email
- Click Verify & Enable
Once enabled, you'll see a green "Enabled" badge on the 2FA card.
Using 2FA During Login
- Enter your email and password as usual
- You'll be redirected to the verification page
- Check your email for a verification code
- Enter the 6-digit code
- Click Verify to complete login
Tip: Codes expire after 5 minutes. Click "Resend Code" if needed.
Sensitive Actions
With 2FA enabled, these actions require email verification:
| Action | What happens |
|---|---|
| Change Password | OTP field appears in the password form |
| Delete Account | OTP required before account deletion |
Verifying Sensitive Actions
- In the action form, click Send Code
- Enter the 6-digit code from your email
- Complete the action as normal
Disabling 2FA
- Go to Settings → Security
- Click Disable 2FA
- Enter the verification code sent to your email
- Click Verify & Disable
Warning: Disabling 2FA reduces your account security.
Troubleshooting
Not receiving verification codes?
- Check spam/junk folder - Codes come from
notifications@optivationai.com - Verify your email - Ensure your account email is correct in Settings
- Wait and retry - There's a 60-second cooldown between code requests
- Check email filters - Whitelist
optivationai.comdomain
Code expired?
Codes are valid for 5 minutes. Click Resend Code to get a new one.
Locked out?
If you can't access your email:
- Contact your team administrator
- They can disable 2FA from the admin panel
- Or contact support at support@optivationai.com
Security Notes
- Codes are single-use - Each code can only be used once
- Rate limited - Maximum 5 OTP requests per 15 minutes
- Secure delivery - Codes are sent only to your verified email
- No SMS option - Email-only for security (SMS is vulnerable to SIM swapping)
FAQ
Q: Is 2FA required?
A: No, 2FA is optional. However, we strongly recommend enabling it.
Q: Can I use an authenticator app?
A: Currently only email-based 2FA is supported. Authenticator app support may be added in future updates.
Q: Does 2FA affect team members?
A: No, each user controls their own 2FA settings independently.
Q: What if my email is compromised?
A: If you suspect your email is compromised, contact support immediately to secure your account.