Skip to main content

Multi-Factor Authentication

Elestio protects your account with MFA. Two methods are available.

  • Email-based MFA (default) — A one-time code is emailed on each login.
  • TOTP MFA — A code is generated by an app on your phone, so your account stays safe even if your mailbox is compromised.

We recommend TOTP for all users. Enable it in a few clicks from your dashboard, under User profile › Security.

Account security tab

Two-factor authentication settings

Enable TOTP MFA​

  1. Open account security.
  2. Click Configure under Manage Two-Factor Authentication.
  3. Select the Authenticator App tab.
  4. Install an authenticator app: Authy (recommended), Google Authenticator, or Microsoft Authenticator.
  5. Scan the on-screen QR code with your app.
  6. Enter the generated code on the Elestio screen.
  7. Click Validate.

Strong MFA is now required to sign in.

Keep your recovery secret

Save the text version of the secret (shown in orange in the screenshot) somewhere safe. It lets you recover access if you lose your phone or authenticator app.

Lost access?

If you lose both your authenticator app and the text secret, contact support by email with proof of identity to have MFA removed.

Enable email-based MFA​

  1. Open account security.
  2. Click Configure under Manage Two-Factor Authentication.
  3. Select the Email Based tab.
  4. Click Enable.

Email-based MFA setup

Disable MFA​

  1. Open account security.
  2. Click Configure under Manage Two-Factor Authentication.
  3. Select the Disabled tab.
  4. Type disable in the confirmation field.
  5. Click Disable.

Disabling MFA