Skip to main content

How to enable Multi-Factor Authentication (MFA)

Secure access to your account with two-step verification via WhatsApp or email

Multi-Factor Authentication (MFA) in WAX

Multi-Factor Authentication (MFA) strengthens the security of your WAX account by requiring a verification code in addition to your password. Even if your credentials are compromised, only verified users can access their account thanks to a unique code sent to their WhatsApp number or by email.

When is MFA required?

If MFA is enabled for your organization, all members must go through it when logging in.

You'll be prompted for MFA when:

  • You haven't logged in for more than 10 days.

  • You've logged out.

  • You're logging in from a new device.

  • You're using private/incognito browsing.

How does MFA work?

1/ Provide or confirm your phone number (optional)

  • If your organization uses MFA and we don't have your number yet, you'll be asked for it before the code is sent.

  • If your organization uses MFA and we already have your number, you'll be asked to confirm it (the first time only) before the code is sent.

2/ Receive a verification code

WAX sends you a one-time code via WhatsApp.

  • The code is valid for 5 minutes.

  • You can request a new code after 30 seconds, or by changing your authentication method.

  • If you receive several codes, only the most recently received one is valid, the others become invalid.

3/ Enter the code

  • If the code is valid, you're logged in automatically.

  • If the code is invalid or expired, you can try again.

4/ Use email instead (optional)

You can also choose "Receive the code by email" to authenticate via email instead of WhatsApp.

Managing MFA for your organization

To enable MFA, admins can go to Settings > Organization Settings > MFA.

✅ When MFA is enabled, all members must authenticate with MFA.
🔕 When MFA is disabled, members can log in with just their email and password.

Did this answer your question?