Ask a human
waxTable

Security & privacy

Multi-factor authentication

Multi-factor authentication adds a second step to sign-in, so even a stolen or guessed password can't get into your account on its own.

4 min readUpdated 18 Jun 2026

Why turn it on

A password is a single point of failure. People reuse them, share them and fall for phishing. Multi-factor authentication (MFA) requires something you know (your password) plus something you have (a code from your phone or authenticator app), so one leaked credential isn't enough to get in.

Set it up

You enable MFA from your account security settings. Have your phone and an authenticator app ready before you start.

  1. Open your security settings

    Go to your account settings and find the multi-factor authentication option. Your overall account is described in your profile.

  2. Add a factor

    Scan the on-screen code with your authenticator app, which then generates a rotating one-time code.

  3. Confirm the code

    Enter the current code from your app to prove the link works and activate MFA.

  4. Save your recovery codes

    Store the recovery codes somewhere safe and offline. They let you back in if you lose your device.

Signing in with MFA on

After MFA is enabled, signing in takes one extra step: enter your password, then the current code from your authenticator app. The code changes every few seconds, so an old code won't work.

  • Keep your device's clock accurate — authenticator codes are time-based.
  • If a code is rejected, wait for the next one and try again.
  • Never share a code with anyone, including someone claiming to be support.

If you lose your device

Losing your phone shouldn't lock you out permanently. That's what your recovery codes are for.

  • Use a saved recovery code to sign in, then re-add MFA on your new device.
  • If you've lost both your device and your recovery codes, you'll need to verify your identity with us.
  • See login and access issues for the recovery path, or contact support.

MFA for teams

Encourage everyone who can edit, approve or send documents to enable MFA. Combined with right-sized roles, it limits the damage a single compromised account can do.

Set roles and access deliberately — see team members and roles and permissions. MFA on accounts plus least-privilege roles is a strong baseline.

Frequently asked questions

What kind of second factor does waxTable support?

Time-based one-time codes from a standard authenticator app are the common method. Open your account security settings to see the options available to you.

Will MFA slow down every sign-in?

Only slightly — you enter one short code after your password. Most people leave a trusted browser signed in and rarely re-enter it.

I changed phones. How do I move MFA across?

Sign in with a recovery code, remove the old factor in your security settings, then add MFA again on the new device.

Can an admin reset MFA for a colleague?

Account recovery requires identity verification. Start with login and access issues, or email support if a team member is locked out.

Is MFA required, or optional?

We strongly recommend it for everyone. For specific organisation-wide requirements, email support.

Still need a hand?

Waxe answers most questions right inside the app. For everything else, our team replies within one business day.

Email support