Skip to main content
Pria supports opt-in Multi-Factor Authentication (MFA) with two methods you can use separately or together:
  • Email verification — a 6-digit code sent to your account email address.
  • Authenticator app — a 6-digit code from Google Authenticator, 1Password, or any compatible app, backed by single-use backup codes.
When either method is on, sign-ins from a new browser or network require a code — whether you sign in with a password or with Google, GitHub or Facebook. Browsers you’ve already verified stay trusted for 7 days, so day-to-day use stays frictionless.
Who should turn this on? Anyone with admin privileges is strongly encouraged to enable MFA — admin accounts can manage users, data, and billing. Standard users can opt in voluntarily.

Turning MFA on

Open Your Profile from the avatar in the top-right and switch to the Security tab. The Two-step verification section lists both methods — turning on either one protects your account.

Email verification

Switch on the Email verification toggle. That’s it — from your next sign-in on a new device, Pria emails a 6-digit code to the address you sign in with. Since you’re already signed in as that email identity, no confirmation step is needed to enable it.

Authenticator app

1

Click 'Set up authenticator app'

Pria shows a QR code, plus a manual setup key in case you can’t scan.
2

Scan the QR code

Add the account to Google Authenticator, 1Password, or any compatible authenticator app.
3

Enter the 6-digit code from your app

Type the current code and click Verify & turn on. The authenticator only activates once you’ve proven the app is generating valid codes — you can’t lock yourself out with a half-finished setup.
4

Save your backup codes

Pria shows a set of single-use backup codes exactly once. Copy or download them and store them somewhere safe — they’re your way back in if you lose your authenticator. You can regenerate a fresh set at any time from the same panel (which invalidates the old set).

Signing in once MFA is on

1

Sign in normally — password or OAuth

Enter your credentials (or click the Google / GitHub / Facebook button) as usual.
2

Pria checks for a trusted device

If you’re using the same browser within the 7-day window and your network hasn’t changed dramatically, you go straight in — no code prompt.
3

Enter a code if prompted

On a new browser, after a long break, or from a different network, Pria asks for a 6-digit code from your preferred method. If you have both methods on, you can switch — for example Send an email instead, or Use a backup code if you can’t reach your authenticator. On success this browser becomes trusted.
Email codes expire in 5 minutes. If you mistype 5 times in a row, the code is burned — click Resend code to get a new one (there’s a short cooldown between resends). Authenticator codes simply roll over to the next code in your app.
“Trusted” doesn’t mean “forever”. Trusted-device status expires after 7 days. If you sign out and back in on the same browser, you stay trusted — the trusted-device status survives logout. If you clear cookies, you’ll re-verify on the next login.

Managing your trusted devices

From Your Profile → Security → Two-step verification, the Sign out trusted devices button revokes every browser you’ve previously verified. The next login from any device — including the one you’re using now — requires a fresh code. Useful when:
  • You signed in on a shared / public computer and forgot to log out properly
  • You lost or sold a device that had access
  • You want to refresh your security posture after a suspected password compromise
This action does not sign you out of your current session — your active session keeps working until normal expiry. It only removes the MFA-skip trust, so your next fresh login forces verification.

Turning MFA off

Each method turns off independently:
  • Email verification — switch the toggle off.
  • Authenticator app — click Turn off authenticator app and confirm. Your backup codes stop working too.
When you turn off your last remaining method, two-step verification is off entirely: Pria clears your trusted-device list (so lingering trust can’t bypass a future re-enable), records the change in the audit log, and leaves your active session alone. Your next sign-in proceeds normally with just password or OAuth.

Recovery

If you’ve lost access to your second factor:
  • Authenticator app lost: use one of your backup codes at the sign-in prompt (each works once). If email verification is also on, you can have a code emailed instead.
  • No working method left (lost mailbox access, no backup codes): contact your Digital Twin’s administrator — they can turn MFA off on your account from the admin Users panel, which also clears the authenticator so you can set it up again.
  • If you are an administrator: another admin on your Digital Twin can do the same for you. If no other admin is available, contact the Praxis AI team at humans@praxis-ai.com.

What gets logged

Every MFA-related action — enabling or disabling a method, codes issued and verified, wrong codes, backup-code use, trusted devices added or revoked — is written to a security audit log. Administrators with the appropriate permission can review these events. The log is for compliance and security audit; it contains only metadata (timestamps, IP, browser), never your password or the actual codes.