Skip to main content
Protect your QuivaWorks account with multi-factor authentication (MFA) and passkeys.

Why Enable MFA?

Stronger sign-in

A stolen password on its own is no longer enough to reach your account

Phishing resistance

Passkeys are bound to the site that issued them and can’t be replayed elsewhere

Account recovery

Enabling MFA issues recovery codes you can use if you lose your device
QuivaWorks prompts you to set up MFA each time you log in until it’s enabled, and the setup screen offers Set Up Later. MFA is never mandatory for any role — but we strongly recommend enabling it.

Setting Up Multi-Factor Authentication

Both methods live in the same place: open Settings from your user menu, then the Password and authentication tab.

Recovery Codes

Recovery codes give you a way back in if you lose your MFA device.
Store recovery codes in a password manager, an encrypted file, or a physical safe. Never leave them in email, a shared document, or unencrypted notes.

How they work

  • You receive 10 codes
  • Each code can be used once
  • Issuing a new set invalidates the old one

Viewing your recovery codes

  1. Open Settings → Password and authentication
  2. Scroll to the Recovery codes section
  3. Click View to see the current set, or Get New to issue a fresh one
An email notification is sent whenever recovery codes are viewed.

Using a recovery code

On the two-factor challenge screen, switch to the Recovery Code method tab, enter one of your codes, and continue. Issue a new set afterwards if you’re running low.
If you’ve used all your codes, a root or admin user can issue a new set for you from Issue new recovery codes in the Users dot menu.

Password Management

Password requirements

Your password must be:
  • At least 8 characters and at most 72 characters
  • Containing at least one uppercase letter
  • Containing at least one lowercase letter
  • Containing at least one number
  • Containing at least one special character
Common words are rejected.
Use a password manager to generate and store a long, unique password.

Changing your password

  1. Open Settings → Password and authentication
  2. In the Password section, click Change password
  3. Confirm your identity — changing a password requires passing two-factor authentication first
  4. Enter and confirm your new password
All your other sessions are terminated; your current session stays signed in. You’ll receive an email confirming the change.

Forgot your password?

1

Start the reset

On the login screen, click Forgot Password, enter the email address associated with your account, and click Reset Password. Only the email address is needed.
2

Follow the link in your email

You’ll receive an email containing a password reset link.
3

Set a new password

Open the link, enter a new password meeting the requirements above, and confirm it.
Reset links are valid for 2 days. Request a new one if yours has expired.
Resetting your password from the emailed link while signed out terminates every session on the account — including any an attacker is holding. A confirmation email is sent either way.

Security Notifications

You’ll receive an email for these events:

Password changed

When your password is changed or reset

Email change requested

When a change to your email address is initiated, and again when it completes

Passkey added

When a new passkey is registered

Recovery codes viewed

When your recovery codes are accessed
If you receive a notification for something you didn’t do, follow the incident response steps straight away.

Best Practices

Never reuse a password across services. A password manager makes this practical.
Set it up when you create your account rather than after an incident.
A password manager or a physical safe. Not email, not shared notes.
Passkeys can’t be phished or replayed, and they’re faster to use than a one-time code.
A backup passkey on another device saves you from falling back to recovery codes.
Check active sessions periodically and terminate anything you don’t recognise.

Troubleshooting

  1. Use a recovery code to log in
  2. Set up a new MFA method immediately
  3. Issue a new set of recovery codes
  4. If you’ve lost your recovery codes too, ask a root or admin user to issue a new set from the Users dot menu
  • Check your device’s clock is synchronised — TOTP depends on accurate time
  • Use the current code; they refresh every 30 seconds
  • Remove and re-add the account in your authenticator app
  • Use a recovery code if the problem persists
  • Confirm your device and browser support passkeys
  • Register a backup passkey on another device
  • Fall back to your authenticator app or a recovery code
  • Check your spam or junk folder
  • Confirm you entered the correct email address — the reset form matches on email alone
  • Allow a few minutes for delivery, then request another reset

Next Steps

API Keys

Secure programmatic access

Sessions

Manage active sessions

Security Overview

Platform and account security

Incident Response

What to do if an account is compromised