Skip to main content
Lerian Console completes the second verification step for users who already have multi-factor authentication enabled. Account enrollment and method management are available through the Identity API. This page covers the Console sign-in experience only.

Before you start


You need:
  • an active user account with authenticator-app or email MFA enabled.
  • access to the selected method or an unused recovery code.
  • a Console deployment configured to handle MFA sign-in.

Complete the second verification step


After the password or SSO step succeeds, the Console opens the MFA verification page.
1

Select a method

Use the preferred method or select another enabled method.
2

Get the passcode

For an authenticator app, open the app and read the current code. For email, select Email, request the code with Resend, then open the message.
3

Enter the passcode

Enter the six-digit passcode and continue.
After the first email request, use Resend again only when the previous message did not arrive. The Console enforces a cooldown, and Auth limits resend attempts.

Use a recovery code


Select the recovery-code option when an enrolled method is unavailable. Enter one unused recovery code.
A recovery code works once. Store the remaining codes securely after sign-in.

Recover from a failed verification



Multi-factor authentication

How MFA enrollment, verification, and recovery work.

Manage MFA via API

Enroll methods, select a preference, and manage recovery codes.

MFA deployment requirements

Configure Auth and the Console for MFA sign-in.