Choose at least two recovery paths
A passkey uses your device or password manager to resist phishing. A TOTP authenticator produces a six-digit rotating code. Recovery codes are single-use backups for times when the primary factor is unavailable.
- Register a passkey on a device or password manager you control.
- Enable an authenticator app when you want a portable code-based factor.
- Generate recovery codes and store them offline, separate from your password.
Complete an MFA sign-in
After the first sign-in step, Astral asks for an available second factor. Use a passkey, a current authenticator code, or one unused recovery code. A recovery code is consumed after a successful check.
Sensitive actions require a fresh check
Creating or revoking API keys, changing custom domains or billing, revoking sessions, and deleting the account can require a recent MFA step-up. Astral keeps technical API error codes stable so clients can distinguish a missing step-up from another failure.
If a factor is lost
- Try another registered passkey or authenticator device.
- Use one saved recovery code.
- After regaining access, remove the lost factor, register a replacement, and regenerate recovery codes.
Note: Astral cannot display an old TOTP secret or used recovery code. Do not send factors or recovery codes to support.