> ## Documentation Index
> Fetch the complete documentation index at: https://muveya.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Account security

> Protect your personal account with an authenticator app, understand what the second factor protects today and what to do if you lose it.

**Account security** is where you add a second factor to your personal muveya account: a six-digit code from an authenticator app (TOTP), such as Google Authenticator, Microsoft Authenticator, 1Password or Authy.

<Info>
  The second factor is **optional** on muveya today. No action in the console or the API asks for it, whether or not you set it up. Once you set it up, though, every sign-in to your account asks for the code. See [What the authenticator protects today](#what-the-authenticator-protects-today).
</Info>

## Who can do it

Any signed-in person, for their own account. No permission is needed. You must have an active dental clinic selected, because the console checks your membership before it starts the setup. If none is active, the screen only shows **Choose a dental clinic**.

The authenticator belongs to your **personal account**, not to one dental clinic: the same code works in every clinic you belong to.

## Where

Open `console.muveya.com/account/security`. The screen is titled **Account security** with the description **Protect your account with a code from an authenticator app.**

<Note>
  The console menu has no link to this screen: type or bookmark the address. The same setup form also opens inside the **Verify your identity** dialog, from its **Set up authenticator** button, when muveya asks you to verify (see [When muveya asks you to verify](#when-muveya-asks-you-to-verify)).
</Note>

## Set up an authenticator

How you start depends on how you signed in.

<Tabs>
  <Tab title="You signed in with a password">
    <Steps>
      <Step title="Confirm your password">
        Enter your current **Password** and select **Set up authenticator**. muveya checks it with the identity provider and does not store it.
      </Step>

      <Step title="Add the account to your app">
        The screen shows **Add this account in your authenticator app using the QR code or the setup key.**, the **Setup key** and your **Recovery codes**. In your authenticator app, choose the option to add an account with a key and type or paste the **Setup key**. The QR code is shown only when one is available; the setup key always works.
      </Step>

      <Step title="Save the recovery codes">
        Copy the **Recovery codes** somewhere safe. The screen warns: **Save these codes somewhere secure before continuing. Each code can be used once if you lose your authenticator. They will not be shown again.**
      </Step>

      <Step title="Verify">
        Type the current six-digit code from the app in **Verification code** and select **I saved my recovery codes. Verify**.
      </Step>
    </Steps>
  </Tab>

  <Tab title="You signed in with Google">
    <Steps>
      <Step title="Start within five minutes of signing in">
        Your account has no muveya password, so Google is the confirmation. The screen says **You need to have signed in with Google within the last five minutes to set up your authenticator.** Select **Set up authenticator**.
      </Step>

      <Step title="Add the account to your app">
        Type or paste the **Setup key** in your authenticator app, as in the password tab.
      </Step>

      <Step title="Save the recovery codes">
        Copy the **Recovery codes** somewhere safe. They will not be shown again.
      </Step>

      <Step title="Verify">
        Type the current code in **Verification code** and select **I saved my recovery codes. Verify**.
      </Step>
    </Steps>

    The Google confirmation can start one setup per Google sign-in, within five minutes of it. If more time passed, or you already started a setup with that sign-in, select **Sign in again**, sign in with Google and come back to this screen right away.
  </Tab>
</Tabs>

When the code is accepted, the screen shows **Authenticator verified. Your account is protected with a second factor.**

To stop without finishing, select **Close setup**. The setup key and recovery codes disappear from the screen and are never saved by the console. The **Sign in again** link is always available under the form.

<Warning>
  Treat the setup key and the recovery codes like passwords. The console shows them only while you set up, and never puts them in the address bar, in a file or in the browser's storage.
</Warning>

### What the system records

* Your personal account is enrolled with the identity provider. From now on, every sign-in needs the code.
* Your current session is marked as verified at that moment.
* muveya does not store your password, the setup key or the recovery codes.

## Sign in with the authenticator

After you set it up:

* **Password sign-in:** on the sign-in screen, open **I have a verification code** and type the code in **Verification code** before you select **Sign in**. Without the code the sign-in is refused with **Check your email, password and verification code, if you use one. Then try again.**
* **Google sign-in:** after Google, the console shows **Verify your identity** (**Enter the six-digit code from your authenticator app.**). Type the code and select **Verify code**.

See [Sign in](/docs/en/account/sign-in) for the rest of the sign-in flow.

## Verify your identity again

When your authenticator is verified, **Account security** shows a **Verify your identity** button. It opens a dialog with **Enter the six-digit code from your authenticator app.**, a **Verification code** field and **Verify code**. A correct code renews the verification of your current session. It changes nothing else.

## What the authenticator protects today

| Area | Today on muveya |
| - | - |
| Signing in with a password | Protected: the code is required once you set up the authenticator. |
| Signing in with Google | Protected: the code is required after Google once you set up the authenticator. |
| Sensitive actions in the console | Not enforced: the actions below are marked as sensitive, but muveya does not ask for the code before them. |
| Public API | API keys are machine credentials. MCP uses a personal OAuth connection authorized after Console sign-in. |

The actions marked as sensitive are:

* **Team:** inviting a person, resending and revoking an invitation, changing a role, changing permissions, changing location and warehouse access, suspending, reactivating, removing and transferring ownership.
* **Order approvals:** approving and rejecting an order.
* **Inventory:** moving a box to another warehouse, adjusting a box, putting a box or a lot in quarantine, marking a box as expired, disposing of a box, submitting a count and deciding a stock correction request.
* **Catalog:** starting a catalog import and requesting a catalog export.

Delivery steps (picking, dispatch, delivery, receipt and close) are not marked as sensitive.

### When muveya asks you to verify

The console already knows how to handle a request for a second factor, in case muveya turns enforcement on. The message is **Verify your identity to continue.** with a **Verify your identity** button. After a correct code the message becomes **Your identity is verified. Try the action again.** and you repeat the action: the console never repeats it for you. A verification would count for five minutes.

If you have no authenticator yet, the dialog offers **Set up authenticator**, and from the setup **Use an existing authenticator** takes you back to the code.

## If you lose your authenticator

The console on production has no screen to remove or replace an authenticator, and no field where you can type a recovery code: the **Verification code** field accepts only six digits.

<Steps>
  <Step title="Try your app's backup">
    If your authenticator app has a cloud backup or runs on another device, restore it there. The same account keeps producing valid codes.
  </Step>

  <Step title="Write to support">
    If you cannot get a code, write to [team@muveya.com](mailto:team@muveya.com) **from the email address of your muveya account**. Do not send your password, the setup key or recovery codes by email.
  </Step>

  <Step title="Meanwhile">
    Ask a person who manages your team for anything urgent. They can suspend your membership if you think someone else may have your phone or your password (see [Team](/docs/en/account/team)).
  </Step>
</Steps>

Keep your recovery codes anyway, as the setup screen asks. They are the only copy muveya ever showed you.

## What can go wrong

| Message | Why | What to do |
| - | - | - |
| **Enter your password.** | You selected **Set up authenticator** with an empty **Password**. | Type your current password. |
| **Sign in again to confirm your identity, then return to account security.** | The password is wrong; or, for Google accounts, more than five minutes passed since your Google sign-in or that sign-in already started a setup. | Check the password, or select **Sign in again** and come back right away. |
| **An authenticator is already configured. Sign in with your current verification code.** | Your account already has an authenticator. | Keep using it. To replace it, see [If you lose your authenticator](#if-you-lose-your-authenticator). |
| **Enter a six-digit verification code.** | The code is not six digits. | Type the six digits shown in the app. |
| **Check the code in your authenticator app and try again. If the attempt expired, start a new sign-in.** | The code is wrong or expired. | Wait for the next code and try again. Check that your phone's clock is set automatically. |
| **This dental clinic is no longer available to your account. Choose another clinic.** | Your membership in the active clinic is no longer active. | Choose another clinic, then return to this screen. |
| **We could not connect. Check your connection and try again.** | No network. | Check your connection. |
| **The service is temporarily unavailable. Please try again shortly.** | The identity provider did not answer as expected. | Try again later. If it persists, write to [team@muveya.com](mailto:team@muveya.com). |

## Related pages

<CardGroup cols={2}>
  <Card title="Sign in" icon="right-to-bracket" href="/docs/en/account/sign-in">
    Password, Google and verification code sign-in.
  </Card>

  <Card title="Team" icon="users" href="/docs/en/account/team">
    Suspend a member whose device may be compromised.
  </Card>

  <Card title="Security and privacy" icon="lock" href="/docs/en/trust/security-and-privacy">
    How muveya protects accounts and data.
  </Card>

  <Card title="Troubleshooting" icon="life-ring" href="/docs/en/help/troubleshooting">
    Fixes for common problems.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.