Existing User Login Flow
When an existing user logs in, the system checks the MFA status on their account and directs them through one of two paths.
Step 1: Login Page
Navigate to the Login page, enter your username or email and password, solve the CAPTCHA, and click Login. If your credentials are incorrect, an error is displayed. If credentials are valid, the system checks your MFA status.
Step 2: MFA Status Check
- If MFA is not yet set up, you are directed through Path A to complete MFA setup.
- If MFA is already configured, you are directed through Path B to verify your identity.
Path A — MFA Not Yet Set Up
Step 3: Set Up Two-Factor Authentication
A Set Up Two-Factor Authentication modal appears. It displays your phone number on file (masked, e.g. (***) ***-6053) and prompts you to confirm or enter a different number. Click Send Verification Code to send an OTP to the displayed number.
Step 4: Enter OTP and Enable MFA
Enter the 6-digit code and click Verify & Enable MFA. MFA is now fully configured. You may also click Change number to use a different phone, or Resend Code once the timer expires.
Step 5: Dashboard
After MFA is enabled, you are redirected to the Dashboard. All future logins will follow Path B.
Path B — MFA Already Configured
Step 3: Choose Verification Method
A Choose Verification Method modal appears with two options: SMS and TOTP. SMS sends a one-time code to your registered phone. TOTP uses a code from your authenticator app (available only if you have enrolled a TOTP device).
Step 4: OTP Verification
- If you selected SMS: enter the OTP received via SMS and click Verify. If valid, you are redirected to the Dashboard.
- If you selected TOTP: see the Logging In with TOTP section below.
Step 5: Dashboard Access
Once the OTP or TOTP code is confirmed, a session is created and you are granted full access to the Dashboard.
Updating Your MFA Phone Number
A logged-in user can update the phone number linked to their MFA from the Profile / Account Settings page. The new number must be verified via OTP before the change is saved.
Step 1: Open Account Settings
While logged in, navigate to your Profile or Account Settings page. Your current phone number is displayed (masked) alongside a MFA Enabled status badge. Click Edit or Change to update the number.
Step 2: Enter New Phone Number
In the Edit Account Settings form, type your new mobile phone number in the Mobile Phone Number field and click Send OTP.
Step 3: OTP Sent to New Number
A verification OTP is sent to the new phone number via SMS. The screen confirms the code has been sent.
Step 4: Enter OTP and Verify
Enter the OTP received on your new phone into the Enter OTP code field and click Verify OTP. If valid, click Confirm Changes. If invalid, an error is shown and you may re-enter or resend.
Step 5: Confirmation
After the OTP is verified and changes are confirmed, your account settings page shows a success banner. The new phone number is now your MFA contact for all future logins.
Authenticator App (TOTP)
TOTP (Time-based One-Time Password) is an optional second-factor method that generates 6-digit codes via a compatible authenticator app such as Google Authenticator, Authy, or Microsoft Authenticator. Once enrolled, you can choose TOTP instead of SMS at login. SMS MFA remains available as a backup at all times.
Note: SMS MFA must already be enabled on your account before you can enroll a TOTP device. If SMS MFA is not active, the Authenticator App card on your profile will appear locked and the Enable button will be disabled.
Logging In with TOTP
Step 1: Username and Password
Navigate to the Login page, enter your credentials, complete the CAPTCHA, and click Login.
Step 2: Choose Verification Method
A Choose Verification Method modal appears. Click TOTP to proceed. Selecting TOTP skips the SMS step entirely — no code is sent over SMS.
Step 3: Enter 6-Digit Code from Authenticator App
Open your authenticator app and enter the current 6-digit code for this account. Click Verify. If the code is invalid, the page shows an error and you may try again.
Step 4: Login Completed
Once the portal confirms the code, you are redirected to the Dashboard.
Removing the Authenticator App
Step 1: Click “Remove”
Log in and navigate to your Profile or Account Settings page. On the Authenticator App card, click the Remove button. An inline confirmation panel appears with Yes, remove it and Cancel buttons.
Step 2: Confirm Removal
Click Yes, remove it. The portal sends a delete request to remove the TOTP factor.
Step 3: Card Resets to “Not Set Up”
The Authenticator App card reverts to the Not set up state. Your account remains protected by SMS MFA. You can re-enroll a TOTP device at any time by clicking Enable again.