MeshanicsDocs
Security

Authenticator app sign-in

Every interactive Meshanics console user completes authenticator-app setup before receiving a console session. This applies to tenant users and Meshanics platform staff. API keys, device certificates, and release-authorizer keys use separate authentication paths and are not affected.

First sign-in

After your password or one-time email link is accepted, scan the QR code with a TOTP-compatible application. Google Authenticator, Microsoft Authenticator, 1Password, Aegis, and other RFC 6238 applications work. If scanning is not available, enter the displayed setup key manually.

Enter the current six-digit code to activate the factor. The console then shows one-time recovery codes. Store them in a password manager or another protected location. Meshanics cannot display them again.

Later sign-ins

Enter the current six-digit code after the primary sign-in step. A code is valid only for its short time window and cannot be reused. You may enter one unused recovery code if the authenticator device is unavailable. A used recovery code is consumed immediately.

If time-based codes are repeatedly refused, confirm that the device running the authenticator has automatic date and time enabled. Repeated attempts are rate limited.

Administrative reset

An organization administrator can reset another member's authenticator from the Team page. Authorized platform staff can do the same from Users. A reset does not reveal the previous secret. It invalidates existing browser sessions for that user and requires a new setup ceremony at the next sign-in.

Never send a QR code, setup key, current code, or recovery code to Meshanics support.