The second factor is optional on muveya today. No action in the console or the API asks for it, whether or not you set it up. Once you set it up, though, every sign-in to your account asks for the code. See What the authenticator protects today.
Who can do it
Any signed-in person, for their own account. No permission is needed. You must have an active dental clinic selected, because the console checks your membership before it starts the setup. If none is active, the screen only shows Choose a dental clinic. The authenticator belongs to your personal account, not to one dental clinic: the same code works in every clinic you belong to.Where
Openconsole.muveya.com/account/security. The screen is titled Account security with the description Protect your account with a code from an authenticator app.
The console menu has no link to this screen: type or bookmark the address. The same setup form also opens inside the Verify your identity dialog, from its Set up authenticator button, when muveya asks you to verify (see When muveya asks you to verify).
Set up an authenticator
How you start depends on how you signed in.- You signed in with a password
- You signed in with Google
1
Confirm your password
Enter your current Password and select Set up authenticator. muveya checks it with the identity provider and does not store it.
2
Add the account to your app
The screen shows Add this account in your authenticator app using the QR code or the setup key., the Setup key and your Recovery codes. In your authenticator app, choose the option to add an account with a key and type or paste the Setup key. The QR code is shown only when one is available; the setup key always works.
3
Save the recovery codes
Copy the Recovery codes somewhere safe. The screen warns: Save these codes somewhere secure before continuing. Each code can be used once if you lose your authenticator. They will not be shown again.
4
Verify
Type the current six-digit code from the app in Verification code and select I saved my recovery codes. Verify.
What the system records
- Your personal account is enrolled with the identity provider. From now on, every sign-in needs the code.
- Your current session is marked as verified at that moment.
- muveya does not store your password, the setup key or the recovery codes.
Sign in with the authenticator
After you set it up:- Password sign-in: on the sign-in screen, open I have a verification code and type the code in Verification code before you select Sign in. Without the code the sign-in is refused with Check your email, password and verification code, if you use one. Then try again.
- Google sign-in: after Google, the console shows Verify your identity (Enter the six-digit code from your authenticator app.). Type the code and select Verify code.
Verify your identity again
When your authenticator is verified, Account security shows a Verify your identity button. It opens a dialog with Enter the six-digit code from your authenticator app., a Verification code field and Verify code. A correct code renews the verification of your current session. It changes nothing else.What the authenticator protects today
The actions marked as sensitive are:
- Team: inviting a person, resending and revoking an invitation, changing a role, changing permissions, changing location and warehouse access, suspending, reactivating, removing and transferring ownership.
- Order approvals: approving and rejecting an order.
- Inventory: moving a box to another warehouse, adjusting a box, putting a box or a lot in quarantine, marking a box as expired, disposing of a box, submitting a count and deciding a stock correction request.
- Catalog: starting a catalog import and requesting a catalog export.
When muveya asks you to verify
The console already knows how to handle a request for a second factor, in case muveya turns enforcement on. The message is Verify your identity to continue. with a Verify your identity button. After a correct code the message becomes Your identity is verified. Try the action again. and you repeat the action: the console never repeats it for you. A verification would count for five minutes. If you have no authenticator yet, the dialog offers Set up authenticator, and from the setup Use an existing authenticator takes you back to the code.If you lose your authenticator
The console on production has no screen to remove or replace an authenticator, and no field where you can type a recovery code: the Verification code field accepts only six digits.1
Try your app's backup
If your authenticator app has a cloud backup or runs on another device, restore it there. The same account keeps producing valid codes.
2
Write to support
If you cannot get a code, write to team@muveya.com from the email address of your muveya account. Do not send your password, the setup key or recovery codes by email.
3
Meanwhile
Ask a person who manages your team for anything urgent. They can suspend your membership if you think someone else may have your phone or your password (see Team).
What can go wrong
Related pages
Sign in
Password, Google and verification code sign-in.
Team
Suspend a member whose device may be compromised.
Security and privacy
How muveya protects accounts and data.
Troubleshooting
Fixes for common problems.