Muin is in private beta.Watch the public release announcement —talk to us.
Falaah Falaah AI

Two-Factor Authentication

Enable two-factor authentication (2FA) on your Muin account with an authenticator app, SMS, or email codes. Save backup codes and manage your method.

Two-factor authentication (2FA) adds a second verification step to sign-in: even if someone learns your password, they can’t get in without your second factor. For organizations handling donor data, finances, and personnel records, we strongly recommend every member enables it.

Choose a Method

Muin supports three 2FA methods:

MethodHow it worksBest for
Authenticator appA 6-digit code from an app like Google Authenticator, Microsoft Authenticator, or 1Password — works offlineMost secure; recommended
SMSA code texted to your phoneSimple, if you keep your number current
EmailA code sent to your account emailWhen you can’t use an app or SMS

Enabling 2FA

  1. Go to Settings → Security and find Two-Factor Authentication in the Security Overview.
  2. Click Enable.
  3. For the authenticator app: scan the QR code with your app, then enter the 6-digit code it shows to confirm the pairing.
  4. Save your backup codes. They’re shown exactly once when 2FA is activated — store them in a password manager or another safe place. Each 8-character code works one time if you ever lose your method.

From then on, sign-in asks for a code after your password. Check Trust this device on a personal machine to skip the code there — see Trusted Devices & MFA Recovery.

Managing Your 2FA

All from Settings → Security:

  • Change method — switch between authenticator app, SMS, and email without disabling protection.
  • Change phone — update the number SMS codes go to.
  • New Codes — regenerate your backup codes (confirm with your password); old codes stop working immediately.
  • Disable — turns 2FA off (requires your password). Your organization may not allow this if 2FA is enforced.

When Your Organization Requires 2FA

Administrators can enforce 2FA for the whole organization. If enforcement is on and you haven’t enrolled, you’ll see a one-time enrollment screen right after sign-in — pick a method and complete setup before continuing into the app. There’s no skip: the requirement protects everyone’s data, not just yours.

Frequently Hit Snags

  • Codes keep getting rejected — authenticator codes are time-based; make sure your phone’s clock is set to automatic.
  • New phone — install your authenticator app on the new device before wiping the old one, or use a backup code to sign in and re-enroll.
  • No more backup codes — generate a fresh set from Settings → Security → New Codes while signed in.