GetMyBot Knowledge Base

Two-factor authentication

Protect your account with an authenticator app, recovery codes, and trusted devices.

On this page

Two-factor authentication (2FA) adds a second proof after your password. MyBot uses time-based one-time passwords (TOTP), the RFC 6238 standard supported by common authenticator apps such as 1Password, Authy, Google Authenticator, Microsoft Authenticator, and hardware or desktop authenticators that support TOTP.

Enrol an authenticator

Open Account → Security, choose Set up two-factor authentication, and confirm your password. Scan the QR code with your authenticator app, or enter the displayed setup key manually. The QR code and setup key are shown only while the enrolment is unfinished. Enter a current six-digit code to finish.

After confirmation, save the recovery codes shown by MyBot. They are shown once only. Keep them in a password manager or another secure offline location; do not put them in a chat, a ticket, or a shared document.

Sign in, recover access, and trust a browser

After the password step, enter one authenticator code or one recovery code. A recovery code is consumed when it succeeds. You may choose Trust this device on a personal browser; a trusted-device token expires, rotates after use, and can be revoked from Account → Security. Do not trust a shared or public computer.

If a device is lost, use a saved recovery code and then revoke that device. If you have no authenticator and no recovery code, MyBot support cannot disclose, reset, or retrieve a TOTP secret, recovery code, or trusted-device token. Use the account-recovery procedure available to your organization before enabling an enforced policy.

Change or turn off 2FA

From Account → Security you can list and revoke one device or all trusted devices, regenerate recovery codes, or disable 2FA. These sensitive actions require a recent password confirmation and a valid authenticator or recovery code. Regenerating codes invalidates unused old codes. Disabling 2FA revokes trusted devices and invalidates recovery codes.

Bot policy and roles

Only the bot owner can require 2FA for bot members in Settings → Bot access. The policy page shows affected members before confirmation and keeps an account-security remediation path available for a member who must enrol. Operators use the support workspace according to their bot role; they cannot inspect anyone’s TOTP secret, recovery codes, or trusted-device tokens.

Audit records identify the security action, actor, and result. They do not contain passwords, authenticator codes, QR payloads, recovery codes, or trusted-device tokens.