Administration
MFA and Passkeys
Learn how to enroll MFA or passkeys, save recovery codes, enforce MFA org-wide, and recover a lost device
Updated June 5, 2026
Rivolq supports both TOTP-based MFA (authenticator apps) and passkeys (WebAuthn, the phishing-resistant standard).
Enrolling MFA
Go to Settings then Security then Set up MFA:
- 01Choose a method: an authenticator app such as Google Authenticator, 1Password, or Authy, or a passkey backed by a YubiKey, your phone's secure enclave, or Touch ID/Face ID.
- 02Scan the QR code or register the passkey.
- 03Save your recovery codes offline.
- 04Verify with a one-time code to complete enrollment.
Passkeys are better than TOTP because they are phishing-resistant and faster. Use passkeys where supported, with TOTP as a backup.
Org-wide enforcement
Under Settings then Security then MFA enforcement, choose Optional, Required for admins, or Required for all. Required for all is right for any production org with sensitive data.
Recovery codes
You receive 10 single-use recovery codes. Save them in a password manager or a printed sheet in a locked drawer, not in email or a phone photo.
Lost device
- 01Sign in with a recovery code on another device.
- 02Go to Settings then Security then Reset MFA.
- 03Re-enroll with the new device; the old enrollment is invalidated. An admin can reset MFA via Settings then Team, the user, then Reset MFA, which is logged. Enroll at least two methods to avoid lockouts.
Still need help?
Reach out for broken behavior, account-specific help, or billing questions.