Set up multi-factor authentication (MFA)

MFA adds a second verification step to your Simbase sign-in. With MFA enabled, signing in requires both your password and a six-digit code from an authenticator app on your phone, so even if your password leaks, your account stays protected.

This takes about a minute to set up, and you only do it once per user.

Before you start

You need:

  • An authenticator app on your phone. Any TOTP-compatible app works: Google Authenticator, 1Password, Authy, Microsoft Authenticator, Bitwarden. If you don't have one, install one from your app store before continuing.

  • Access to your Simbase account in the dashboard (you'll need to sign in normally first).

Enable MFA

  1. Sign in to dashboard.simbase.com.

  2. Open SettingsPersonal details.

  3. Toggle Multi-Factor Authentication on. The dashboard shows a QR code and a setup key.

  4. Save the setup key somewhere safe, such as your password manager. It's how you restore MFA if you lose your phone.

  5. In your authenticator app, add a new account and scan the QR code. If you can't scan, paste the setup key instead.

  6. Enter the six-digit code the app generates and click Verify.

MFA is now active. The next time you sign in, you'll be prompted for a code after entering your password.

Sign in with MFA

  1. Go to dashboard.simbase.com and enter your email and password as usual.

  2. When prompted, open your authenticator app and find the Simbase entry.

  3. Enter the current six-digit code.

  4. You're in.

For how long is the code valid?The code changes every 30 seconds. If it changes mid-typing, use the new one.

Combining MFA with passkeys

If you also have a passkey set up, signing in with the passkey alone satisfies both factors. You won't be prompted for an MFA code on top. This is the recommended setup for the best balance of security and friction.

You can have both methods enabled simultaneously; they're complementary, not exclusive.

Disable MFA

You can disable MFA at any time, but don't unless you have a strong reason. To turn it off:

  1. Open SettingsPersonal details.

  2. Toggle the Multi-Factor Authentication switch off.

  3. Confirm.

After disabling, sign-in falls back to email + password alone. Re-enable any time using the same flow.

Common questions

If you saved the setup key when you enabled MFA, add it to an authenticator app on your new phone and use it to sign in. If you have a passkey, use that instead. Contact support if neither applies.

Any TOTP-compatible app works, and the same code will do. Use whichever you already have.

No. MFA is a per-user setting, so each person enables it on their own profile. There's no account-wide enforcement.

Likely a clock-drift issue. TOTP codes depend on synchronised time. Check that the time on your phone is set to "automatic" (network-provided), then try again.

  • Passkeys, phishing-resistant alternative or complement to MFA

  • Users, managing team access