Customer portal — two-factor sign-in and recovery codes
This page explains how extra sign-in security works in the customer portal for people who use an authenticator app and optional recovery codes. It is written for customers and support staff; technical implementation details are in Technical — Customer MFA and recovery codes.
Why two-factor sign-in exists
Your organization may ask you to add a second step when you sign in—usually a 6-digit code from an app on your phone (for example Google Authenticator or Authy). That way, even if someone learns your password, they still need your device to get in.
Recovery codes
When you finish setting up the authenticator, the portal may show you a list of recovery codes (sometimes called backup codes).
- Save them in a safe place—for example a password manager or a secure note that only you can access.
- Each code can typically be used once, on its own, if you lose access to your authenticator app (for example you replace your phone).
- Treat them like passwords: do not share them or store them in plain sight.
If your organization allows it, you may be able to create new recovery codes from Settings after proving it is really you (for example with your password and a code from your authenticator). Creating new codes usually replaces the old list—save the new list again.
When you have no recovery codes left
If you use your last recovery code, the portal may show a clear message that no recovery codes are left, and you may receive an email reminding you to create new codes in Settings when you can.
If you are locked out of both your authenticator and your recovery codes, contact your Ethica support or the channel your organization uses—staff can help through the right internal process.
Related
- Customer portal — overview of the portal.
- Technical — Customer MFA and recovery codes — for engineers.