- Is it mandatory to set up an authenticator app during onboarding?
No. It's one of three options - passkey, authenticator app, or SMS OTP.
Pick whichever fits your device and agency policy. You can add or change methods later from your Settings page.
- How do I set up an authenticator app during onboarding?
- On the "Secure Your Account" screen, select "Authenticator app."
- You'll see a QR code as the primary option and a manual setup key just below it.
- Scan the QR from your authenticator app, or copy the key if you can't scan. Then enter the 6-digit code your app shows to confirm. It takes under a minute.
- The QR code is on my desktop, and my authenticator is also on my desktop; how do I scan it?
You don't need to. Click "Copy" next to the manual setup key and paste it into your authenticator app (1Password, Bitwarden, Authy desktop all accept a pasted key).
Then enter the 6-digit code to verify.
- What if I start setting up an authenticator app but cancel halfway?
No problem. The pending secret is discarded, and you return to the "Secure Your Account" screen. Nothing is saved if you cancel.
- What are backup codes, and why do I need to save them?
After you verify your authenticator app, Ethos shows you 1 single-use backup code. Each one works exactly once if you ever lose access to your authenticator. You can download, print, or copy them - but you can't have them emailed, since routing recovery through email defeats the purpose of MFA. You must confirm "I have saved these codes" before setup completes.
- What happens if I close the page before saving the backup codes?
Setup is cancelled. Your authenticator is not enrolled. You'll have to start over.
- If I choose SMS or passkey during onboarding, can I add an authenticator app later?
Yes. Go to Settings → Account Settings → Account Security → Add authenticator anytime after onboarding. All three methods are independent — adding one never removes the others.
Updated