Turn on two-factor authentication and add a passkey
Two-factor authentication and passkeys live on the Profile tab of Settings, which opens when you click your name in the sidebar. The tab has a Two-factor authentication card and a Passkeys card. Where Google or Microsoft sign-in is set up for your Mesy, it also has a Sign-in methods card.
Turn on two-factor authentication
Section titled “Turn on two-factor authentication”You need an authenticator app on your phone. To enrol:
- Click Enable two-factor authentication.
- Enter your Current password and click Continue. Accounts without a password skip this step.
- Scan the QR code with your app, or copy the key shown under Can’t scan? Enter this key manually: and paste it into the app.
- Click Continue.
- Enter the 6-digit Verification code from the app and click Verify.
- Save the 10 recovery codes with Copy or Download, then click Done.
- Read the card, which now says Enabled and shows how many recovery codes remain.
Mesy shows the recovery codes once. Each code signs you in a single time if you lose your authenticator. When 3 or fewer remain, the card asks you to regenerate a fresh set.
From then on, signing in asks for your Verification code after your password. Click Use a recovery code to enter one instead. If you’ve added a passkey and your browser supports passkeys, Use your passkey instead appears too.
Regenerate or disable
Section titled “Regenerate or disable”Click Regenerate recovery codes, confirm with your Current password (or click Use an authenticator or recovery code instead) and click Regenerate. The new set replaces every old code, and the old codes stop working at once.
Click Disable to switch two-factor off. Mesy asks you to confirm, then to prove it’s you the same way, and deletes your recovery codes. If your workspace requires two-factor authentication and you have no passkey, Mesy refuses and tells you to ask an admin to lift the requirement.
Add a passkey
Section titled “Add a passkey”A passkey signs you in with your fingerprint, face, device PIN or a security key, and it counts as your second factor. To add one:
- Click Add a passkey.
- Type a Name (optional), such as the device it lives on.
- Click Create passkey and follow your browser’s prompt.
- Find the passkey listed on the card with the date it was added.
If your browser doesn’t support passkeys, the card says so and hides Add a passkey; you can still rename or remove the ones you have. Click Rename to change a passkey’s name and Save. Click Remove and confirm to delete one from Mesy; this doesn’t remove it from your device’s password manager.
Mesy won’t remove your only way in. If a passkey is your only sign-in method, removal fails with Cannot remove your only sign-in method. If your workspace requires two-factor authentication and the passkey is your only second factor, removal fails until you add another method.
Manage your sign-in methods
Section titled “Manage your sign-in methods”The Sign-in methods card lists the Google or Microsoft logins linked to your account. A Link Google or Link Microsoft button appears for each provider set up for your Mesy that you haven’t linked yet. Click it; you’re sent to the provider and returned to Settings. Click Unlink and confirm to remove one. Removing your only sign-in method is refused here too.
If you signed up through Google or Microsoft and have no password, the card also shows Set a password. Enter a New password and Confirm password, then click Set Password, so you can still sign in if social login is unavailable.
When your admin requires two-factor authentication
Section titled “When your admin requires two-factor authentication”An admin turns this on in Admin, under Organization, with the Require two-factor authentication switch. At your next sign-in, after Mesy accepts your password, it shows “Your workspace requires two-factor authentication. Set it up to finish signing in.” Choose Authenticator app to run the enrolment above, or Passkey to create one. The Passkey option appears only in a browser that supports passkeys. Back to sign in cancels and leaves you signed out. While the requirement is on, you can’t disable your last second factor.
If support resets your two-factor authentication
Section titled “If support resets your two-factor authentication”When a support operator resets your authenticator, Mesy sends you an in-app notification titled Two-factor authentication was reset. This notification can’t be muted. The reset removes your authenticator and recovery codes but leaves your passkeys in place. Without a passkey, your next sign-in works without a code, or lands in the setup flow above if your workspace requires two-factor authentication. With a passkey, sign-in still asks for it. Turn the authenticator back on from the Two-factor authentication card.