Multi-Factor Authentication
Set up and manage multi-factor authentication for enhanced account security.
Last updated: February 2026
Why Use Multi-Factor Authentication
Multi-factor authentication (MFA) adds a second layer of security beyond your password. Even if someone obtains your password, they cannot access your account without your second factor.
Available Authentication Methods
EasyBook supports three MFA methods. You can enable one or more to suit your preferences.
Authenticator App (TOTP)
Use an authenticator app such as Google Authenticator, Authy, or any TOTP-compatible app to generate time-based codes.
- Go to Settings and open Security
- Click Enable MFA and select Authenticator App
- Scan the QR code with your authenticator app
- Enter the 6-digit code displayed in the app to verify
- Save your recovery codes in a secure location
Passkeys (WebAuthn)
Passkeys provide modern passwordless authentication using your fingerprint, face recognition, or a hardware security key.
- Go to Settings and open Security
- Click Add Passkey
- Follow the browser prompt to register your device biometric or security key
- Give your passkey a recognizable name for easy identification
A verification code is sent to your registered email address. This method is used as a fallback when other methods are not available.
Email One-Time Password
When you enable MFA, you receive a set of one-time-use backup codes. These codes allow you to regain access if you lose your primary MFA device.
- No additional setup is required
- Uses the email address on your account
- Code expires after a short period for security
Recovery Codes
For certain sensitive actions, EasyBook may ask you to verify your identity again even if you are already signed in. This is called step-up authentication.
- Each recovery code can only be used once
- Store your codes in a password manager or other secure location
- You can generate a new set of codes at any time, which invalidates the previous set
Step-Up Authentication
When prompted, simply verify with your configured MFA method to continue.
- Changing your password: Requires re-verification to confirm your identity
- Modifying MFA settings: Requires verification before changes take effect
- Accessing financial data: Requires verification to protect sensitive business information
You can update your MFA configuration at any time.
Managing Your MFA Settings
As an organization owner or admin, you can help keep your organization secure by encouraging MFA adoption.
- Go to Settings and open Security
- View your active MFA methods and add or remove methods as needed
- To disable MFA entirely, remove all configured methods and confirm with your current verification
MFA for Your Team
While MFA cannot currently be enforced at the organization level, it is strongly recommended for all users with access to sensitive data.
- Recommend MFA to all team members during onboarding
- View which team members have MFA enabled in the team settings
- MFA protects not just individual accounts but the entire organization's data
Recovery Email
Add a recovery email address to your account as an additional safeguard. The recovery email is a separate email address used only for account recovery if you are locked out of your primary email and MFA methods.
- Go to Settings and open Security
- Find the Recovery Email section
- Enter a different email address that you control
- Click the verification link sent to the recovery email to confirm it