# MFA & Recovery

Add a passkey or authenticator app and keep recovery codes available if you lose a method.

Multi-factor authentication (MFA) adds another check before sensitive account actions. You can use a passkey or authenticator app and keep recovery codes as a backup.

Open **[Security](https://testnet.polyester.com/account/settings/security)** to see your methods, add another one, or replace a method you no longer use.

## Choose an MFA method

## Passkey

A passkey uses Face ID, Touch ID, a device PIN, or a compatible hardware security key. It is quick to use and resistant to phishing.

Check whether your passkey syncs across trusted devices or stays only on the device where you created it.

![Name your passkey, then save it with Touch ID](https://media.polyester.com/cdn-cgi/image/width=800,quality=80,format=auto,fit=scale-down/content-assets/a/fd9fd8d64dc3cd2f7d3f3e44bb9603750506eea4aaf5db54c18fcc165e7ee3ee/source.webp)

## Authenticator app

An authenticator app generates a new six-digit code at regular intervals. Scan the setup QR code once, then enter the current code to finish enrollment.

Protect the setup QR code and secret. Anyone who copies either can generate valid codes.

![Name your authenticator, then scan the QR code and enter the 6-digit code](https://media.polyester.com/cdn-cgi/image/width=800,quality=80,format=auto,fit=scale-down/content-assets/a/ef4014d67390a7fc5e5545350fed4766e188e94efd99a4e048f81acd23233d4f/source.webp)

## Set up MFA

1. Open Security

   Go to [Security](https://testnet.polyester.com/account/settings/security) and find Multi-Factor Authentication.

2. Add your first method

   Choose a passkey or authenticator app and complete the device or code prompt.

   ![Set up MFA with Passkey or Authenticator app](https://media.polyester.com/cdn-cgi/image/width=800,quality=80,format=auto,fit=scale-down/content-assets/a/40b7b523096f1397b5f64700438cbe624c685a4f765deb9be4ef1ed57b9c248e/source.webp)

3. Name the method

   Use a label that helps you recognize the device or authenticator without including a secret.

4. Save your recovery codes

   Store the codes somewhere protected and separate from your primary device.

5. Add a backup method

   Enroll another method so one lost device does not lock you out of protected actions.

## Recovery codes

Recovery codes let you complete an MFA challenge when your usual method is unavailable. Each code works once.

- Keep them out of email, chat, screenshots, support tickets, source code, and browser autofill.
- Remove a code from your saved set after using it.
- Regenerating codes replaces the entire previous set.

> **New recovery codes replace the old set**
>
> Do not close the new-code window until the replacement codes are stored safely. Every code from the previous set stops working after regeneration.

## Manage your methods

The Security page shows when each method was added and last used. Rename a method when a clearer label would help, or remove a method you no longer control.

You cannot remove your final MFA method. Add and test its replacement first, then remove the old method.

## When Polyester asks for MFA

Polyester automatically requests MFA when an action needs more protection. Some actions accept a recent MFA check, while higher-risk changes ask for a fresh verification tied to that request.

Examples include changing security settings, managing API keys, changing whitelists, exporting an embedded owner wallet, or moving funds under an MFA requirement.

## If verification fails

1. Try another enrolled method if one is available.
2. For authenticator codes, check that your device time is correct and enter the newest code.
3. Use one unused recovery code when your regular methods are unavailable.
4. If the prompt is unfamiliar, stop and review [Sessions & Alerts](https://testnet.polyester.com/docs/user-docs/account/access-and-security/sessions-alerts-and-recovery).

Polyester support never needs your authenticator secret, current code, passkey credential, or recovery code.

## FAQ

### What does multi-factor authentication (MFA) protect if my wallet is already secure?

Your wallet controls your Polyester account. MFA adds a separate verification check before sensitive actions in the app, including but not limited to withdrawals, transfers, and changes to security settings or API keys. You can use a passkey or authenticator app and keep recovery codes as a backup. It adds another layer of protection on top of keeping your wallet and sign-in identity secure.

### Should I choose a passkey or an authenticator app?

Preferably both. Polyester lets you set up more than one MFA method, so you have a backup if one becomes unavailable. A passkey uses your device’s biometrics, a device PIN, or a compatible hardware security key. An authenticator app generates time-based six-digit codes. Choose the combination that fits your devices and security habits. [Learn about securing your account.](https://testnet.polyester.com/docs/user-docs/start/secure-account)

### What if I lose my multi-factor authentication (MFA) method or recovery codes?

Polyester recommends setting up multiple MFA methods. If you lose a method or your recovery codes, use another enrolled method or an unused recovery code to add a replacement method, remove a lost one, or generate new codes. If you lose all MFA methods and recovery codes, Polyester cannot replace or recreate an MFA method or regenerate codes for you. Contact support through the chat icon on Polyester. The team can assist, but recovery is not guaranteed.
