Skip to main content

Security

Set up multi-factor authentication (MFA)

ConKarma protects every sign-in with multi-factor authentication. Pick the methods that fit you — a passkey, an authenticator app, SMS, or backup codes — and keep your account yours.

Multi-factor authentication (MFA) asks for a second proof of identity beyond your password when you sign in. ConKarma supports passkeys, authenticator-app codes (TOTP), SMS codes, and one-time backup codes, and lets you choose which is your primary method.

On by default

MFA is on by default for every account, and always on for anyone who pays, is a guardian, or uses the adult zone. You can add or swap methods freely, but turning protection down happens only after a step-up identity check, a clear warning, and a notification to you — never silently.

Choose your methods

Set a primary method and add backups. A passkey (Face ID, Touch ID, or a hardware security key) is the strongest and is phishing-resistant; an authenticator app (TOTP) generates codes offline; SMS is offered as a fallback — we label it clearly because phone numbers can be hijacked through SIM-swap; and one-time backup codes are your safety net. Email is a reset channel, not a true second factor, so it is never counted as your MFA.

Passkeys first

We recommend a passkey as your primary method. It lives in your device's keychain, syncs across your own devices, needs nothing to type, and can't be phished or reused — an attacker with your password still can't get in. If your device doesn't support passkeys yet, an authenticator app is the next-best primary.

Keep backup codes

When you turn on MFA, ConKarma gives you a set of one-time backup codes. Save them somewhere safe — a password manager is ideal. Each code works once; you can regenerate a fresh set anytime from Settings, which immediately retires the old set. Backup codes are the first rung of account recovery if you ever lose a device.

Your MFA is yours

On an adult account your MFA is sovereign: no other member of your cell can disable, reset, or downgrade it. Every change to your methods or recovery options is written to your security log and sends you a notification, so nothing about how you sign in can change behind your back.

Step-up for sensitive actions

Some actions re-check your identity even in the middle of a session: changing your MFA or recovery settings, entering the adult zone, making a purchase, exporting your data, or deleting your account. This step-up means a borrowed, already-unlocked phone still can't do lasting harm.

Frequently asked questions

Which method should I pick?
Is SMS safe to use?
Can someone in my family turn off my MFA?
What happens if I lose my second factor?