Why Enable MFA?
Stronger sign-in
A stolen password on its own is no longer enough to reach your account
Phishing resistance
Passkeys are bound to the site that issued them and can’t be replayed elsewhere
Account recovery
Enabling MFA issues recovery codes you can use if you lose your device
QuivaWorks prompts you to set up MFA each time you log in until it’s enabled, and the setup screen offers Set Up Later. MFA is never mandatory for any role — but we strongly recommend enabling it.
Setting Up Multi-Factor Authentication
Both methods live in the same place: open Settings from your user menu, then the Password and authentication tab.- Passkey (Recommended)
- Authenticator App
Passkeys let you sign in with biometrics or a device PIN instead of a password.
1
Open the tab
Settings → Password and authentication
2
Add a passkey
In the Passkey section, click Add. The screen is titled “Add passkey”.
3
Complete setup
Follow your device’s prompts — Touch ID, Face ID, Windows Hello, a device password, a PIN, or a hardware security key.
4
Save your recovery codes
Store them somewhere safe before you close the screen
Existing passkeys are listed under Manage, where you can remove one or remove them all.
Recovery Codes
Recovery codes give you a way back in if you lose your MFA device.How they work
- You receive 10 codes
- Each code can be used once
- Issuing a new set invalidates the old one
Viewing your recovery codes
- Open Settings → Password and authentication
- Scroll to the Recovery codes section
- Click View to see the current set, or Get New to issue a fresh one
Using a recovery code
On the two-factor challenge screen, switch to the Recovery Code method tab, enter one of your codes, and continue. Issue a new set afterwards if you’re running low.If you’ve used all your codes, a root or admin user can issue a new set for you from Issue new recovery codes in the Users dot menu.
Password Management
Password requirements
Your password must be:- At least 8 characters and at most 72 characters
- Containing at least one uppercase letter
- Containing at least one lowercase letter
- Containing at least one number
- Containing at least one special character
Changing your password
- Open Settings → Password and authentication
- In the Password section, click Change password
- Confirm your identity — changing a password requires passing two-factor authentication first
- Enter and confirm your new password
All your other sessions are terminated; your current session stays signed in. You’ll receive an email confirming the change.
Forgot your password?
1
Start the reset
On the login screen, click Forgot Password, enter the email address associated with your account, and click Reset Password. Only the email address is needed.
2
Follow the link in your email
You’ll receive an email containing a password reset link.
3
Set a new password
Open the link, enter a new password meeting the requirements above, and confirm it.
Resetting your password from the emailed link while signed out terminates every session on the account — including any an attacker is holding. A confirmation email is sent either way.
Security Notifications
You’ll receive an email for these events:Password changed
When your password is changed or reset
Email change requested
When a change to your email address is initiated, and again when it completes
Passkey added
When a new passkey is registered
Recovery codes viewed
When your recovery codes are accessed
Best Practices
Use a unique password
Use a unique password
Never reuse a password across services. A password manager makes this practical.
Enable MFA now, not later
Enable MFA now, not later
Set it up when you create your account rather than after an incident.
Store recovery codes securely
Store recovery codes securely
A password manager or a physical safe. Not email, not shared notes.
Prefer passkeys
Prefer passkeys
Passkeys can’t be phished or replayed, and they’re faster to use than a one-time code.
Register a second passkey
Register a second passkey
A backup passkey on another device saves you from falling back to recovery codes.
Review your sessions
Review your sessions
Check active sessions periodically and terminate anything you don’t recognise.
Troubleshooting
Lost access to your MFA device
Lost access to your MFA device
- Use a recovery code to log in
- Set up a new MFA method immediately
- Issue a new set of recovery codes
- If you’ve lost your recovery codes too, ask a root or admin user to issue a new set from the Users dot menu
Authenticator app codes rejected
Authenticator app codes rejected
- Check your device’s clock is synchronised — TOTP depends on accurate time
- Use the current code; they refresh every 30 seconds
- Remove and re-add the account in your authenticator app
- Use a recovery code if the problem persists
Passkey not recognised
Passkey not recognised
- Confirm your device and browser support passkeys
- Register a backup passkey on another device
- Fall back to your authenticator app or a recovery code
Didn't receive the password reset email
Didn't receive the password reset email
- Check your spam or junk folder
- Confirm you entered the correct email address — the reset form matches on email alone
- Allow a few minutes for delivery, then request another reset
Next Steps
API Keys
Secure programmatic access
Sessions
Manage active sessions
Security Overview
Platform and account security
Incident Response
What to do if an account is compromised