Security
Set up multi-factor authentication (MFA)
ConKarma protects every sign-in with multi-factor authentication. Pick the methods that fit you — a passkey, an authenticator app, SMS, or backup codes — and keep your account yours.
Multi-factor authentication (MFA) asks for a second proof of identity beyond your password when you sign in. ConKarma supports passkeys, authenticator-app codes (TOTP), SMS codes, and one-time backup codes, and lets you choose which is your primary method.
On by default
MFA is on by default for every account, and always on for anyone who pays, is a guardian, or uses the adult zone. You can add or swap methods freely, but turning protection down happens only after a step-up identity check, a clear warning, and a notification to you — never silently.
Choose your methods
Set a primary method and add backups. A passkey (Face ID, Touch ID, or a hardware security key) is the strongest and is phishing-resistant; an authenticator app (TOTP) generates codes offline; SMS is offered as a fallback — we label it clearly because phone numbers can be hijacked through SIM-swap; and one-time backup codes are your safety net. Email is a reset channel, not a true second factor, so it is never counted as your MFA.
Passkeys first
We recommend a passkey as your primary method. It lives in your device's keychain, syncs across your own devices, needs nothing to type, and can't be phished or reused — an attacker with your password still can't get in. If your device doesn't support passkeys yet, an authenticator app is the next-best primary.
Keep backup codes
When you turn on MFA, ConKarma gives you a set of one-time backup codes. Save them somewhere safe — a password manager is ideal. Each code works once; you can regenerate a fresh set anytime from Settings, which immediately retires the old set. Backup codes are the first rung of account recovery if you ever lose a device.
Your MFA is yours
On an adult account your MFA is sovereign: no other member of your cell can disable, reset, or downgrade it. Every change to your methods or recovery options is written to your security log and sends you a notification, so nothing about how you sign in can change behind your back.
Step-up for sensitive actions
Some actions re-check your identity even in the middle of a session: changing your MFA or recovery settings, entering the adult zone, making a purchase, exporting your data, or deleting your account. This step-up means a borrowed, already-unlocked phone still can't do lasting harm.
Frequently asked questions
Which method should I pick?
A passkey if your device supports it — it's the strongest and can't be phished. An authenticator app is an excellent offline second choice. Whatever you choose as primary, keep a set of backup codes.
Is SMS safe to use?
SMS works, but we label it a fallback because phone numbers can be taken over through SIM-swap. Prefer a passkey or authenticator app as your primary method and keep SMS only as a backup.
Can someone in my family turn off my MFA?
No. On an adult account your MFA is sovereign — no cell member can disable or reset it. Children's accounts work differently: a guardian provisions them and can help recover them. See the account-recovery guide.
What happens if I lose my second factor?
That's what account recovery is for — start with a backup code, then a time-delayed self-recovery path, and for children, a guardian. See the account-recovery guide for the full ladder.