What is Multi-Factor Authentication (MFA)?
Multi-factor authentication, or MFA, refers to the use of more than one identity factor to authenticate a user. In addition to entering a username and password, a user needs to confirm a code sent through a second channel, like their email or phone. MFA is more secure than relying on a password alone.
If you only use a password to authenticate a user, it leaves your account vulnerable if that password is weak or has been exposed elsewhere. Requiring a second factor makes it harder for anyone else to access your account, even if they have your password.
Email MFA is Automatic
From October 1, 2026, every zkipster user will be asked to verify their identity with a code when logging in through the browser. By default, this code is sent to the email address on your user profile. There's no toggle to turn on and no setup needed.
Learn more: Managed Multi-Factor Authentication
When you log in, you'll see a prompt asking for a verification code. Check the inbox for the email address on your zkipster profile, enter the code, and you're in.
Step 1: Confirm Your Profile Email Address is Correct
Since your MFA code goes to your profile email, start by making sure it's correct:
1. Click the picture in the top right corner.
2. Open the Edit Profile section.
3. Check the email address listed is correct and update it if needed.
4. Save your changes.
Step 2 (Optional): Add SMS as Alternative MFA Method
If you'd like the option to verify by SMS text message as well as email, you can add a phone number to your profile:
1. Go to the Profile section of your Account Settings.
2. Toggle Multi-Factor Authentication to ON and enter the phone number to use.
3. Click 'Send Code': a verification code will be sent to that number.
4. Enter the code on the verification screen and click 'Verify'.
Once this is set up, you'll receive your login code by both email and SMS, and can use either one.
Please note: If you turn SMS-based verification back off, you'll continue to receive your code by email. This can't be fully disabled, since it's the account-wide baseline method from October 1.
Staying signed in on trusted devices
After you verify a device, you have the option to have zkipster remember it for 30 days, so you won't be prompted for a new code each time you log back in from that device. You'll need to verify again after 30 days, or whenever you log in from a new device or browser.
Does this affect the zkipster mobile app?
No, this enforcement applies to browser login only. You won't be asked for an MFA code when logging into the zkipster Mobile App.



