Overview
Vault supports multi-factor authentication (MFA) to add an extra layer of security to your account. While Vault offers built-in MFA via email or SMS, using a time-based One-Time Password (OTP) authenticator app provides stronger security and works even without internet connectivity. This guide explains how to set up, use, and manage OTP authentication.
OTP authenticator setup is available exclusively for local Vault users. If your organization uses single sign-on (SSO) for authentication, MFA is managed through your SSO provider instead. Check with your administrator if you are unsure which authentication method your account uses.
Set Up Your OTP Authenticator
Step 1: Access My Settings
- Log in to the Vault platform.
- Click your user icon in the bottom-left corner of the screen.
- From the dropdown menu, select My Settings.
Step 2: Enable the Authenticator App
- In the My Settings window, locate the Enable Authenticator App section.
- Click the Enable button.
- A dialog box titled "Two Factor Authentication" will open, beginning with "Authentication Verification."
Step 3: Scan the QR Code
- Open your preferred OTP authenticator app on your phone.
- Scan the QR code displayed on your Vault screen using your authenticator app.
- Your app will generate a six-digit code.
- Enter this code into the field on your Vault screen.
- Click Continue.
Step 4: Save Your Recovery Codes
- The next screen displays "Save Your Security Codes." This is your opportunity to save your recovery codes.
- You will see 10 recovery codes displayed. Each code can be used once to log in if you cannot access your authenticator app.
- Download or copy these codes using the Download or Copy buttons.
- Store them in a secure location, such as a password manager, encrypted file, or physical safe.
- Do not store recovery codes in the same location as your Vault credentials.
- Do not share recovery codes with anyone.
- Click Continue after you have saved your codes.
Step 5: Confirmation
- You will see a confirmation message: "Authenticator App Enabled." This confirms your setup is complete.
- Click Done.
From this point forward, you will need to provide a code from your authenticator app whenever you log in to Vault.
Logging In with Your Authenticator App
Standard Login Process
- Enter your username and password on the Vault login screen.
- On the "Verify Your Identity" screen, select Authenticator App.
- Open your authenticator app on your phone and locate the six-digit code for Vault.
- Enter the code in the field provided.
- (Optional) Check Remember this Browser if your administrator has enabled this feature. This allows you to log in without MFA on this device and network for future sessions, until either changes.
- Click Submit.
Using a Recovery Code
If you do not have access to your authenticator app (for example, if you lose your phone or delete the app), you can use a recovery code instead.
- On the "Verify Your Identity" screen, click Use Recovery Code.
- Enter one of your saved recovery codes in the field provided.
- Click Submit.
- You will gain access to your account.
Each recovery code can only be used once. After use, that code is no longer valid. If you use all your recovery codes, you will need to generate new ones or disable and re-enable your authenticator.
Viewing Your Recovery Codes
- Go to My Settings > Profile.
- In the "Authenticator App Enabled" section, click View Recovery Codes.
- You will see your currently available recovery codes.
- You can download or copy these codes for safekeeping.