For the complete documentation index, see llms.txt. This page is also available as Markdown.

Multi-factor authentication

This page describes using two-factor authentication to secure your Middle account.

Middle supports time-based one-time passwords (TOTP) for multi-factor authentication (MFA).

MFA installation-wide settings

All users are encouraged to set up an authenticator when they log in.

Organization owners can require authenticators in Organization Settings.

To configure these settings, navigate to Settings in the top navbar, then on that page find the Security section, then Require multi-factor authentication (MFA).

To require authenticators for...

  • ...all users, choose "Always required"

  • ...only owners, choose "Required for all owners"

  • ...owners and users with 'write' privileges, choose "Required for all writers"

  • ...no one, choose "Never required"

Setting up MFA

Users can also set up a new authenticator or manage an existing authenticator:

  • Navigate the User Settings page:

    • Find "My Session" in the top navigation bar and navigate to the "User settings" submenu item.

  • Within User Settings, find the Authenticator section

    • If an authenticator is already configured, it can be removed (if allowed by MFA installation-wide settings) or changed to a new authenticator

    • If an authenticator is not configured, one can be added.

Consider consulting with your organization for recommendations on what authenticator to use:

Middle is compatible with any authenticator using the TOTP prototocol, including Google Authenticator, Microsoft Authenticator and 1Password. Using 1Password is recommended due to its ease of use.

Remember to copy your recovery codes just in case you lose access to your authenticator.

Logging in with an authenticator

If you've set up an authenticator, after logging in you'll see this screen.

With 1Password, a configured authenticator will auto-fill, making for a seamless login experience.

Using recovery codes

If you aren't able to log in with your authenticator (perhaps due to a lost or temporarily misplaced authenticator or other issue), you can use a recovery code by clicking the "use a recovery code" link.

Enter one of the recovery codes you saved when setting up an authenticator. That recovery code cannot be used again.

If you've lost your authenticator, we recommend you disconnect the current authenticator and set up a new one.

Last updated

Was this helpful?