Multi-factor authentication and recovery codes

Enrolling a second factor, and what to do when you lose it.

Last updated September 22, 2026

Multi-factor authentication adds a second step to sign-in using an authenticator app. It is required for some roles and available to everyone.

Enrolling

In the Security tab, start enrollment and scan the code with your authenticator app. Enter a code from the app to confirm the two are in sync before enrollment completes. If you do not confirm, nothing changes, so an abandoned attempt cannot half-enroll you.

Recovery codes

Enrollment produces a set of one-time recovery codes. These are the only way back in if you lose the device with your authenticator on it.

Copy or download them at the point they are shown and store them somewhere that is not the phone holding your authenticator. A password manager is fine. A screenshot in the same phone's camera roll is not, because a lost phone takes both.

Each code works once. You are told how many remain, and you can regenerate the set, which invalidates the old one.

Losing your device

Use a recovery code to sign in, then enroll your new device and regenerate your codes. If you have no codes left and no device, an owner or admin in your organization can reset your enrollment. If you are the only owner, your Pytheus contact can help.

What platform staff cannot do

Nobody at Pytheus can see your recovery codes or your authenticator secret, and support access never becomes the ability to sign in as you.