Setting up two-factor authentication
Setting up two-factor authentication
Two-factor authentication (2FA) adds an extra security layer to your Kivly account.
What is 2FA?
Two-factor authentication requires two things to sign in:
- Something you know - Your password
- Something you have - Your phone or authenticator app
Even if someone gets your password, they can't access your account without the second factor.
Why enable 2FA?
Protection against:
- Password theft
- Phishing attacks
- Unauthorized access
- Account takeover
- Data breaches
Benefits:
- Enhanced account security
- Protect personal wellness data
- Meet compliance requirements
- Peace of mind
Methods available
1. Authenticator app (recommended)
- Most secure method
- Works offline
- Apps: Google Authenticator, Authy, 1Password, Microsoft Authenticator
2. SMS text message
- Codes sent to phone
- Requires cell service
- Backup option recommended
3. Backup codes
- One-time use codes
- Store securely
- Use if primary method unavailable
Setting up authenticator app 2FA
Step 1: Enable 2FA
- Go to Settings → Security
- Click Two-Factor Authentication
- Click Enable 2FA
- Enter your password to confirm
Step 2: Choose authenticator app
- Select Authenticator App
- Download app if needed:
- Google Authenticator (iOS/Android)
- Authy (iOS/Android)
- Microsoft Authenticator (iOS/Android)
Step 3: Scan QR code
- Open authenticator app
- Tap "+" or "Add"
- Scan QR code shown in Kivly
- Or manually enter secret key
Step 4: Enter verification code
- App generates 6-digit code
- Enter code in Kivly
- Click Verify
- 2FA is now active!
Step 5: Save backup codes
- Download backup codes
- Store in password manager or safe place
- Each code works once
- Print or save securely
Setting up SMS 2FA
Enable SMS authentication
- Settings → Security → Two-Factor Authentication
- Select SMS Text Message
- Enter phone number
- Click Send Code
- Enter received code
- Verify and enable
Phone requirements
- Must be able to receive SMS
- US and international numbers supported
- Mobile number (not landline)
- Carrier SMS fees may apply
Using 2FA when signing in
Normal sign-in process
- Enter email and password
- Click Sign In
- Enter 6-digit 2FA code from:
- Authenticator app, or
- SMS text message
- Optionally check "Trust this device for 30 days"
- Complete sign-in
"Trust this device" option
- Skip 2FA for 30 days on this device
- Recommended for personal devices only
- Not recommended for shared computers
- Can revoke in Security settings
Using backup codes
When to use:
- Lost phone
- Authenticator app not working
- Can't receive SMS
- Traveling without phone service
How to use:
- Click Use backup code at sign-in
- Enter one backup code
- Code is consumed (can't reuse)
- Successfully sign in
Important:
- Each code works once
- Download new codes after using all
- Keep codes secure like passwords
Managing 2FA
View trusted devices
Settings → Security → Trusted Devices
- See where you're signed in
- Revoke trust from any device
- Review sign-in history
Regenerate backup codes
If codes lost or all used:
- Settings → Security → 2FA
- Click Generate New Backup Codes
- Old codes stop working
- Download and store new codes
Change 2FA method
Switch between authenticator app and SMS:
- Disable current method
- Enable preferred method
- Complete setup
- Download new backup codes
Disabling 2FA
To turn off 2FA:
- Settings → Security → 2FA
- Click Disable Two-Factor Authentication
- Enter password
- Enter current 2FA code
- Confirm disabling
Note: Not recommended. 2FA significantly improves account security.
Troubleshooting
Lost access to authenticator app
Solution:
- Use backup code to sign in
- Disable 2FA
- Set up 2FA again with new device
- Download new backup codes
Wrong code error
Try:
- Ensure correct code (not expired)
- Check device time is accurate
- Try next generated code
- Use backup code instead
Can't receive SMS
Solutions:
- Check phone service
- Verify correct phone number
- Check spam/blocked messages
- Use authenticator app or backup code
Lost backup codes
If can still sign in:
- Generate new codes in Security settings
If locked out:
- Contact support@kivly.org
- Provide identity verification
- Support will assist recovery
Account recovery without 2FA access
If completely locked out:
- Click Can't access 2FA? at sign-in
- Follow account recovery process
- Verify via alternate email
- Answer security questions
- Support verification may be required
Recovery takes:
- 24-72 hours for security
- Identity verification required
- May need subscription info
- Photo ID potentially needed
Security best practices
Protect your 2FA:
- Don't share authenticator app
- Keep backup codes secure
- Use password manager
- Enable on all important accounts
- Review trusted devices monthly
Additional security:
- Strong, unique password
- Recovery email set up
- Security questions answered
- Activity alerts enabled
- Regular account reviews