FAQs — Reapit Connect Multi-Factor Authentication
Answers to common questions about multi-factor authentication (MFA) in Reapit Connect.
Overview
This article answers common questions about multi-factor authentication (MFA) in Reapit Connect. For the administrator's view — resetting MFA for staff and enforcing it office-wide — see the Master User article in the related links.
What is MFA and why is it required?
MFA adds a second step to sign-in: a 6-digit code from an authenticator app on your phone, alongside your password. It protects trust accounting, personal data and signed documents even if your password is stolen. Many offices enforce it for all users, and it is required for users with financial permissions.
Which authenticator apps can I use?
Any app that supports time-based one-time passwords (TOTP), including Microsoft Authenticator, Google Authenticator, Authy and 1Password. Reapit does not require a specific app.
I got a new phone. How do I move MFA across?
If your old phone still works, some apps (Microsoft Authenticator, Authy, 1Password) can transfer or sync accounts to the new phone — do this before wiping the old one. If the old phone is gone, sign in with one of your recovery codes and re-register MFA under My Account › Security, or ask your Master User to reset your MFA so you can enrol the new phone.
What are recovery codes and where are mine?
Recovery codes are single-use codes shown when you first set up MFA, for signing in without your phone. Each code works once. If you didn't save them, sign in normally, go to My Account › Security and select Regenerate recovery codes — this invalidates the old set.
My code is being rejected but it looks right. Why?
TOTP codes depend on your phone's clock. Enable automatic date and time in your phone settings, wait for a fresh code, and try again. Also check you are reading the code from the correct account entry in the app — old entries from a previous MFA reset no longer work and should be deleted.
I'm locked out — no phone and no recovery codes. What do I do?
Contact your office's Master User, who can reset your MFA after verifying your identity. You'll receive an email prompting you to set up MFA again on next sign-in. If the Master User themselves is locked out, they must contact Reapit support, which requires additional identity verification.
How often will I be asked for a code?
At each new sign-in, on new devices and browsers, and after your session expires. On a trusted office machine you can tick Remember this device for 30 days so codes are only requested monthly — never tick this on a shared or public computer.
Tip: Register MFA on your phone's authenticator app rather than a tablet that stays at the office — the second factor should be something you always have with you.