Ankra supports three second factors, managed from Profile → Authentication:
Enrolling
Open Authentication settings
Click your profile avatar → Profile → Authentication. The two-factor card shows your current status.
Add an authenticator app
Click Set up authenticator app, scan the QR code (or enter the secret manually), and confirm with a code. On confirmation you receive your recovery codes - store them somewhere safe; each works once.
Add a passkey (optional but recommended)
Click Add passkey and follow your browser’s prompt. You can register multiple passkeys and security keys and remove them individually.
You cannot remove your last remaining factor while 2FA is active - add a replacement first.
Signing In with 2FA
After your password (or SSO), Ankra prompts for a second factor. Use a passkey with one tap, enter a TOTP code, or switch to Use a recovery code instead. Repeated failed attempts invalidate the pending login and you’ll need to start over.
Organisation-Enforced 2FA
Organisations can require 2FA for all members. If any of your organisations enforces it and you haven’t enrolled, Ankra shows a Secure your account to continue screen at sign-in and blocks the platform until you complete enrollment.
Managing 2FA from the CLI
The CLI hands 2FA management to the browser, because TOTP enrollment, recovery codes and passkey registration (WebAuthn) all need one:
CLI logins that hit an MFA challenge complete in the browser and hand control back to the terminal automatically. Full command details are in the CLI reference.