Multi-Factor Authentication (MFA)
This section contains essential information and usage guidelines for setting up and managing Multi-Factor Authentication inside your account.
What is Multi-Factor Authentication?
Multi-Factor Authentication (MFA) is a security feature that requires you to verify your identity using a second method every time you log in. In addition to your password, you must provide a one-time verification code — either sent to your registered email or generated by an authenticator app. This ensures that even if your password is compromised, your account remains protected.
When should you use this?
Use this feature when:
You want to add an extra layer of security to your account beyond just a password
You need to protect sensitive bot configurations, customer data, and team access
You are trying to meet security or compliance requirements for your organization
Benefits of Multi-Factor Authentication
🔐 Adds a strong second layer of protection to your account
🛡️ Prevents unauthorized access even if your password is leaked
📱 Supports both email and authenticator app methods for flexibility
🔄 Works seamlessly with Google and Facebook login (OAuth) flows
🗝️ Includes recovery codes for emergency account access
Expected Outcome
After setting this up:
Every login will require a verification code in addition to your password
Unauthorized users will be blocked even if they know your password
You will have recovery codes available as a backup login method
How to Set Up MFA
Accessing the MFA Settings
Go to "More" from the left sidebar and click on "My Account".
Navigate to the "Security" tab

Locate the "Multi-Factor Authentication" dropdown and click to expand it.
Click "Setup" or "Select MFA Method" to begin the setup process.

There are two authentication methods available:
Email
Authenticator Application
Method A: Email Verification
In the "Choose Authentication Method" popup, select the "Email" card and click "Continue".

A verification code will be sent to the email address linked to your account. Open your inbox and retrieve the code.
Enter the code in the verification field on screen and click "Verify".

Method B: Authenticator App
In the "Choose Authentication Method" popup, select the "Authenticator App" card and click "Continue".

On the next screen, set up the authenticator app using one of two methods:
Scan the QR code shown on screen using Authenticator App.
Copy the secret key shown and manually enter it into your authenticator app

Once the app shows a 6-digit code, enter it in the "Verification Code" field on screen and click "Verify".

Saving Recovery Codes
After setup is complete, a set of recovery codes will be displayed on screen. Click "Download" to save them immediately.

Critical: Recovery codes are shown only once. Once you leave this page, they cannot be retrieved again. Store them somewhere safe.
Logging In with MFA Enabled
Once MFA is set up, the login flow changes as follows:
Enter your email and password (or log in via Google/Facebook OAuth) as usual.
You will be prompted to verify your identity. If both email and authenticator app methods are active, you can choose either. If only one is set up, that method is shown automatically.
Enter the verification code from your chosen method and click "Verify".
If the code is correct, you are logged in successfully.
You have 3 attempts to enter the correct verification code. After 3 failed attempts, your account will be temporarily locked. Wait for the cooldown period to expire before trying again.
Logging In with a Recovery Code
If you cannot access your email or authenticator app, you can use a recovery code to log in.
On the verification screen, select the option to use a recovery code
Enter one of your saved recovery codes and click "Verify"
Each recovery code can only be used once. Once used, it is permanently invalidated.
Best Practices
🔐 Download and store your recovery codes in a secure location (password manager, encrypted file) immediately after setup
📱 Use Google Authenticator or Microsoft Authenticator for app-based MFA — avoid lesser-known apps
⏱️ If your authenticator app code is not working, ensure your device's clock/time is correctly synced
🎯 Set up MFA before sharing account access with team members to enforce account-wide security
Troubleshooting
FAQs
Related Articles
Managing My AccountPasswordSupport
If you still have questions for our team, write to us at support@botpenguin.com. We'll get back to you within 48 hours.
🎉 Congratulations, you have successfully completed this section! Your account is now secured with Multi-Factor Authentication.
Last updated
Was this helpful?