TOTP
Authenticator apps that generate 6-digit codes.
Multi-factor authentication (MFA) adds a second factor to your Rack Gateway account. The web UI supports TOTP and WebAuthn, plus backup codes for recovery.
TOTP
Authenticator apps that generate 6-digit codes.
WebAuthn
Security keys and passkeys (YubiKey, Touch ID, Windows Hello).
Backup Codes
One-time recovery codes generated during enrollment.
If MFA is required by your organization, you will be redirected to Account Security after login.
Some sensitive actions require MFA verification even with an active session. Examples include:
The step-up window defaults to 10 minutes and is configurable by admins.
You can trust a device during verification or from Account Security → Trusted Devices. Trusted devices skip MFA prompts until their TTL expires (default 30 days).
Backup codes are generated during enrollment and can be regenerated later. Codes are only shown at generation time, so store them securely.
The CLI supports MFA verification:
rack-gateway deploy -a myapp --mfa-code 123456rack-gateway deploy -a myapp --mfa-method webauthnIf you use WebAuthn with the CLI, mark the method as CLI Compatible in Account Security.
Admins configure global MFA settings in Settings: