Multi-Factor Authentication Setup
Multi-factor authentication (MFA) adds a second verification step to your login, protecting your account even if your password is compromised. AlchemOS Positive supports authenticator app TOTP and SMS as MFA methods.
Why MFA matters
AlchemOS Positive accounts hold sensitive sustainability data, verified emission records and financial offset purchase history. MFA significantly reduces the risk of unauthorised access.
Organisation admins: MFA can be made mandatory for all users in Settings → Security → Require MFA. Users without MFA will be prompted to set it up on next login.
Enabling MFA on your account
- Click your avatar (top-right) → Account Settings
- Select the Security tab
- Under Two-Factor Authentication, click Enable
Authenticator app (recommended)
- Open your authenticator app (Google Authenticator, Authy, Microsoft Authenticator, 1Password, etc.)
- Scan the QR code shown on screen, or manually enter the setup key
- Enter the 6-digit code from the app to confirm setup
- Download and save your recovery codes (10 one-time codes)
- Click Activate
SMS (fallback)
- Enter your mobile phone number (with country code)
- Click Send verification code
- Enter the 6-digit code received by SMS
- Click Activate
SMS is a fallback option. Authenticator apps are more secure and recommended.
Logging in with MFA
After entering your email and password:
- You will be prompted: "Enter your authentication code"
- Open your authenticator app and enter the current 6-digit code
- Click Verify
Codes are valid for 30 seconds. If the code has just expired, wait for the next one.
Recovery codes
Recovery codes allow you to log in if you lose access to your MFA device. Each code can only be used once.
- Store recovery codes in a password manager or secure offline location
- Generate new recovery codes at any time in Account Settings → Security → Regenerate Codes (this invalidates existing codes)
- If you have used 5 or more codes, regenerate a new set
Changing or removing MFA
To change the MFA method:
- Account Settings → Security → Two-Factor Authentication → Change method
- Set up the new method and verify
- The old method is automatically removed
To remove MFA entirely (if allowed by your organisation's security policy):
- Account Settings → Security → Two-Factor Authentication → Disable
- Enter your current MFA code to confirm
If your organisation has Required MFA enabled, you cannot disable it. Contact your Admin.
Locked out of your account
If you have lost your MFA device and do not have recovery codes:
- Contact your organisation Admin
- Admins can reset MFA for any user from Settings → Users → → Reset MFA
- You will receive an email prompting you to set up MFA again on next login
If you are the sole Admin, contact support@alchemos.io for identity-verified account recovery.
MFA for API access
MFA applies to browser-based login only. API access uses dedicated API keys — see API Keys.