Identity.Base Docs

Multi-Factor Authentication

Identity Base ships with multiple MFA options so hosts can choose the right assurance and recovery model. MFA is configured in the host and then exercised by the browser clients through the standard `/auth/mfa/*` flows.

TOTP (Authenticator Apps)

Google Authenticator, Authy, or any RFC 6238 compliant authenticator application.

SMS (Twilio)

One-time challenge codes delivered by SMS through the configured Twilio integration.

Email Challenges

Verification codes delivered via the configured email sender, such as MailJet or SendGrid.

Recovery Codes

Single-use backup codes for account recovery when the primary MFA method is unavailable.

Operational notes

  • Email and SMS methods depend on the corresponding transport configuration being present and enabled in the host.
  • Recovery codes should be surfaced in your UI as a first-class account recovery mechanism.
  • Browser clients should treat MFA as part of the standard sign-in flow, not as a separate product feature.