Pular para o conteúdo
HeartBadge docs

Two-Factor Authentication

Live

How authenticator codes protect sensitive HeartBadge actions.

Authenticator-based two-factor authentication (2FA) generates a changing six-digit code in a compatible authenticator app. This code is separate from the six-digit code HeartBadge sends by email.

When authenticator 2FA is used

  • Sensitive account changes. HeartBadge may require an authenticator code before changing security settings.
  • Cashout destinations. Adding or changing certain destinations, including a Solana wallet, can require authenticator 2FA.
  • Reward movement. The dashboard may request an additional code when a protected transfer is approved.

Follow the requirement shown in the dashboard for the action you are taking. A passkey and authenticator 2FA both strengthen the account, but some actions may accept one while others require authenticator 2FA specifically.

Set up authenticator 2FA

  1. Sign in to your HeartBadge dashboard.
  2. Open Account Security.
  3. Choose Set up authenticator 2FA.
  4. Scan the setup QR code with a TOTP-compatible authenticator app.
  5. Enter the current six-digit code from the app to confirm setup.
  6. Save the backup codes somewhere private and durable.

Protect the setup secret

The setup QR code and its manual key can generate future authenticator codes. Treat them like a password. Do not send a screenshot to support, store it in a shared folder, or scan a setup code you did not request.

Backup codes

Backup codes are one-time recovery codes for use when the authenticator app is unavailable. Store them separately from the phone or computer running the authenticator. A used backup code cannot be used again.

If you lose your authenticator

  1. Try another device where the authenticator account is available.
  2. Use an unused backup code when the security prompt offers that option.
  3. After regaining access, replace the old authenticator setup and save the new backup codes.
  4. If no accepted method remains, contact support@heartbadge.com. Recovery may require additional verification and may take time.

Turning off 2FA

Removing authenticator 2FA can make protected actions unavailable until another required security method is configured. Review any cashout or destination warnings shown by the dashboard before confirming the change.

HeartBadge support will never ask for your current authenticator code, backup codes, or setup secret.