MFA User Manual
Turn On Two-Factor Authentication for Your SimuLive Account
Also want SimuHost to answer chat questions? See the AI Brain & BYOK User Manual.
Getting Started
Multi-factor authentication (MFA), shown in SimuLive as Two-Factor Authentication, asks for a second proof of identity in addition to your password. Even if someone learns your password, they cannot open your account or change sensitive settings without your code.
Methods Available
| Method | How It Works | Best For |
|---|---|---|
| Authenticator App | A 6 digit code that changes every 30 seconds in an app on your phone | Everyday use, works without a network connection |
| Email Verification | A one-time code sent to your account email | A simple second factor with nothing to install |
| Recovery Codes | 10 single-use codes you save yourself | Getting back in if you lose your other methods |
You can turn on the Authenticator App, Email Verification, or both. Recovery codes are created for you when you turn on your first method.
What You Need
- 1Your current SimuLive password. If you signed up with Zoom, Google or GitHub and never set a password, SimuLive sends you a password reset email the first time you try.
- 2For the Authenticator App, a phone or computer with an authenticator app such as Google Authenticator, Authy, 1Password or Microsoft Authenticator.
- 3For Email Verification, access to the email inbox of your SimuLive account.
Where to Find It
Go to Dashboard → Settings. On the Profile Settings page, click Two-Factor Authentication.
MFA protects the sign in step for accounts that use email and password. Signing in with Zoom, Google or GitHub does not add a SimuLive code step. Once MFA is on, sensitive actions in your account ask for a code however you signed in.
Turn On the Authenticator App
The Two-Factor Authentication window shows your current state and one row for each item: Authenticator App and Email Verification, each with an Enable or Disable button, and Recovery Codes, which appears after a method is on and shows how many unused codes you have with a Reset button.
Confirm Your Password
- 1In the Two-Factor Authentication window, click Enable next to Authenticator App.
- 2Type your current password in the Current Password field.
- 3Click Continue.
If you cannot remember your password, click Forgot Password? and SimuLive sends a reset email. If MFA is already on, you are also asked for a verification code before the change goes through.
Scan the QR Code
- 1On the Scan This QR Code screen, open your authenticator app and choose to add an account.
- 2Scan the QR code on the screen.
- 3If you cannot scan, click Copy secret and enter the key in your app by hand.
- 4Type the 6 digit code that your app now shows into Enter the 6 Digit Code From Your App.
- 5Click Verify and Enable.
You have 10 minutes from the moment the QR code appears to enter your first code. If time runs out, start again from step 1. The QR code and key are unique to your account, so do not share them.
When the code is accepted, the Authenticator App is on. If this is your first method, your recovery codes appear next.
Turn On Email Verification
Email Verification sends a one-time code to your account email each time you sign in.
- 1In the Two-Factor Authentication window, click Enable next to Email Verification.
- 2Type your current password in Current Password.
- 3Click Enable.
Email Verification is on straight away, and SimuLive shows a confirmation that it is enabled. If it is your first method, your recovery codes appear next. Email codes are valid for 5 minutes.
Save Your Recovery Codes
Your recovery codes are your way back into the account if you lose your phone or cannot receive email. Each code looks like XXXXX-XXXXX and works one time.
- 1Ten single-use codes are shown on the Save Your Recovery Codes screen.
- 2Click Download to save them as a text file, or Copy all codes to copy them to your clipboard.
- 3Store them in a password manager or another safe place that is separate from your phone.
- 4Click I've Saved These Codes to finish.
SimuLive keeps only hashed versions of your codes, so it cannot show them to you again. The close button is hidden on this screen until you click I've Saved These Codes. If you lose your codes, regenerate a new set from Manage Your MFA Settings below.
Sign In With MFA
- 1Go to the SimuLive login page and enter your email and password.
- 2In the Two-Factor Verification window, choose your method. The Authenticator and Email tabs appear only when both methods are on.
- 3Enter the 6 digit code and click Verify and Continue.
Using the Authenticator
Open your authenticator app and enter the current SimuLive code. Each app code works once, so if you just used it, wait for the next one.
Using Email
Your code is sent to your account email. Enter it within 5 minutes. To get another code, wait for the 30 second timer to finish and click Resend code. You can request up to 3 resends for one sign in.
Using a Recovery Code
Click Use a recovery code instead, enter one of your saved codes in the format XXXXX-XXXXX and continue. That code is then used up.
You have up to 15 minutes to finish verification, and 5 wrong codes end the attempt. If that happens, sign in again from the beginning.
Passwordless Login
Once the Authenticator App or Email Verification is on, you can turn on Passwordless Login. From then on you sign in with just your email and a verification code, no password needed.
Turn It On
- 1In the Two-Factor Authentication window, find Passwordless Login and switch it on.
- 2Enter your current password to confirm and click Enable.
The toggle is disabled until at least one of Authenticator App or Email Verification is turned on.
Turn It Off
Switch Passwordless Login off and confirm your current password. Your account then asks for your password again at every sign in.
Actions That Ask for a Code
When MFA is on, the following actions pause and open the Verification Required window:
| Action | Where |
|---|---|
| Change your username | Profile Settings |
| Change your password | Profile Settings |
| Delete your account | Profile Settings |
| Cancel a Diamond subscription | Subscription |
| Update your payment method | Subscription |
| Delete a subscription | Subscription |
| Reveal a saved AI provider key | API Keys |
- 1Choose Authenticator or Email. Recovery codes also work through Use a recovery code instead.
- 2Enter the code.
- 3Click Confirm.
If you click Cancel, the action does not go ahead. After 5 wrong codes within 15 minutes, the action is paused, so wait and try again with a new code. Requests for email codes for these actions are limited to 5 in 15 minutes.
Manage Your MFA Settings
Open Dashboard → Settings → Two-Factor Authentication at any time to change your setup. Every change needs your current password. If MFA is already on, it also needs a verification code.
Disable a Method
- 1Click Disable next to the method you want to remove.
- 2Enter your current password and click Disable.
- 3Enter your verification code if asked.
If you disable your last method, MFA turns off and your recovery codes are deleted. Your account is then protected by your password alone.
Regenerate Recovery Codes
- 1Click Reset next to Recovery Codes.
- 2Enter your current password and click Reset. Your existing recovery codes stop working.
- 3Save the new codes the same way as when you first turned on MFA.
Security Alerts
SimuLive sends a security alert email to your account address when a method is turned on or off and when recovery codes are regenerated. If you did not make the change, reset your password straight away and contact support.
The Secure Your Account Reminder
While MFA is off, your dashboard shows a Secure Your Account window that explains why two-factor authentication helps.
| Button | What It Does |
|---|---|
| Enable Now | Opens the Two-Factor Authentication window so you can start setup |
| Remind Me Later | Hides the reminder for the current sign in session. It returns the next time you sign in until MFA is on |
You can also start any time from Settings.
Limits and Timing
| Item | Limit |
|---|---|
| Authenticator setup | Enter your first code within 10 minutes of seeing the QR code |
| Authenticator code | 6 digits, changes every 30 seconds, each code works once |
| Email code | Valid for 5 minutes, resend after 30 seconds, up to 3 resends |
| Sign in verification | Finish within 15 minutes, up to 5 wrong codes |
| Recovery codes | 10 codes, each works once, regenerating replaces the old set |
| Sensitive actions | 5 wrong codes within 15 minutes pauses the action |
| Email codes for sensitive actions | Up to 5 requests in 15 minutes |
MFA and Your AI Provider Keys
If you use SimuHost and AI Brain with your own AI provider keys, MFA also protects those keys. On the API Keys page in your dashboard, keys are always shown masked. To reveal a full key, use the reveal control on that key. When MFA is on, SimuLive asks for a verification code first.
Keys are encrypted at rest, so turning on MFA adds a second lock on top of that protection. See the AI Brain & BYOK User Manual for full key management details.
Troubleshooting
The authenticator code is rejected
Check that the date and time on your phone are set automatically, wait for the next code and try again. Each code works only once.
The QR code expired
Start setup again. The QR code must be used within 10 minutes.
I cannot scan the QR code
Click Copy secret and enter the key in your app by hand.
The email code did not arrive
Check your spam folder, wait for the 30 second timer and click Resend code.
I lost my phone
Click Use a recovery code instead and enter one of your saved codes. Then set up your authenticator app again.
I lost my phone and my recovery codes
Contact support at support@simulive.us from your account email.
Too many wrong attempts
Wait, then try again with a new code. For sign in, start again from the login page.
I have no password to confirm
Click Forgot Password? and follow the reset email, then return to setup.
Frequently Asked Questions
Do I have to turn on MFA?
No. It is optional, but SimuLive reminds you with the Secure Your Account window until you turn it on.
Can I use both methods?
Yes. When both are on, the Two-Factor Verification window shows an Authenticator tab and an Email tab, and you choose one each time.
Which authenticator apps work?
Google Authenticator, Authy, 1Password, Microsoft Authenticator and any other standard authenticator app that supports 6 digit time-based codes.
How many recovery codes do I get, and can I see them again?
You get 10. They are shown once, right after your first method is turned on or after you regenerate them. SimuLive cannot show them again, so keep them safe.
What happens to a recovery code after I use it?
It cannot be used again. When you are running low, regenerate a new set from Settings.
Does MFA apply when I sign in with Zoom, Google or GitHub?
The code step at sign in applies to email and password sign in. Sensitive actions in your account still ask for a code once MFA is on.
Will I be asked for a code every time I open the dashboard?
No. You verify when you sign in and when you perform one of the sensitive actions listed above.
Does SimuLive tell me when my MFA settings change?
Yes. A security alert email is sent when a method is turned on or off and when recovery codes are regenerated.
Can I sign in without a password?
Yes, once you turn on Passwordless Login. It needs the Authenticator App or Email Verification to already be on, and after that you sign in with just your email and a verification code.
Can I turn MFA off?
Yes. Disable each method in Settings. Disabling your last method turns MFA off and deletes your recovery codes.
Need Help?
Cannot find what you are looking for? Our support team is here to help.
support@simulive.us