[{"data":1,"prerenderedAt":544},["ShallowReactive",2],{"content-query-QlhmOKJEWF":3,"content-query-yP1cWMns5L":322,"content-query-W4RtfFQaoh":326,"content-query-eJ9XWy0CGH":351,"content-query-M5aWdXgQKx":364,"content-query-UP87PRcOMw":371,"content-query-7VgBfxLOWV":375,"content-query-9giMhwHrGj":397,"content-query-Z6fTkbgt1D":404,"content-query-j8GGVgf9na":417,"content-query-IVhcXRs1sR":424,"content-query-G03kJtQzJS":434,"content-query-1mvwAKmUBq":456,"content-query-No6iPTj4EO":481,"content-query-zRSmsuVl55":491,"content-query-MsdmgXewTK":495,"content-query-BMhIInEJl2":502},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"intro":10,"type":5,"layout":11,"body":12,"_type":315,"_id":316,"_source":317,"_file":318,"_stem":319,"_extension":320,"sitemap":321},"/docs/account/mfa","account",false,"","Multi-factor authentication (MFA)","Add multi-factor authentication (MFA) to your Webhook Relay account for an extra layer of login security. Available on every plan, including the free tier.","Multi-factor authentication protects your account even if your password is stolen. Turn on app-based (TOTP) MFA in your account settings and keep your recovery codes safe.","doc",{"type":13,"children":14,"toc":305},"root",[15,23,36,43,55,61,121,126,135,141,153,186,212,218,236,242,270,276],{"type":16,"tag":17,"props":18,"children":19},"element","p",{},[20],{"type":21,"value":22},"text","Multi-factor authentication (MFA), sometimes called two-factor authentication (2FA), adds a second step to your login. After your password you also enter a one-time code from an authenticator app, so a leaked or guessed password is no longer enough to access your account.",{"type":16,"tag":17,"props":24,"children":25},{},[26,28,34],{"type":21,"value":27},"MFA is available on ",{"type":16,"tag":29,"props":30,"children":31},"strong",{},[32],{"type":21,"value":33},"every plan, including the free tier",{"type":21,"value":35}," — there is no need to upgrade to secure your account.",{"type":16,"tag":37,"props":38,"children":40},"h2",{"id":39},"how-it-works",[41],{"type":21,"value":42},"How it works",{"type":16,"tag":17,"props":44,"children":45},{},[46,48,53],{"type":21,"value":47},"Webhook Relay uses ",{"type":16,"tag":29,"props":49,"children":50},{},[51],{"type":21,"value":52},"app-based, time-based one-time passwords (TOTP)",{"type":21,"value":54}," — the same standard supported by Google Authenticator, 1Password, Authy, Microsoft Authenticator and most password managers. Your authenticator app and Webhook Relay share a secret once, during setup, and from then on the app generates a fresh 6-digit code every 30 seconds. Nothing is sent over SMS, so there is no SIM-swap risk.",{"type":16,"tag":37,"props":56,"children":58},{"id":57},"enable-mfa",[59],{"type":21,"value":60},"Enable MFA",{"type":16,"tag":62,"props":63,"children":64},"ol",{},[65,89,101,106,111],{"type":16,"tag":66,"props":67,"children":68},"li",{},[69,71,80,82,87],{"type":21,"value":70},"Open your ",{"type":16,"tag":72,"props":73,"children":77},"a",{"href":74,"rel":75},"https://my.webhookrelay.com/account",[76],"nofollow",[78],{"type":21,"value":79},"account details page",{"type":21,"value":81}," and go to the ",{"type":16,"tag":29,"props":83,"children":84},{},[85],{"type":21,"value":86},"Security",{"type":21,"value":88}," section.",{"type":16,"tag":66,"props":90,"children":91},{},[92,94,99],{"type":21,"value":93},"Choose ",{"type":16,"tag":29,"props":95,"children":96},{},[97],{"type":21,"value":98},"Enable two-factor authentication",{"type":21,"value":100},". A QR code and a setup key are shown.",{"type":16,"tag":66,"props":102,"children":103},{},[104],{"type":21,"value":105},"In your authenticator app, scan the QR code (or type the setup key manually).",{"type":16,"tag":66,"props":107,"children":108},{},[109],{"type":21,"value":110},"Enter the 6-digit code from the app to confirm the two are in sync.",{"type":16,"tag":66,"props":112,"children":113},{},[114,119],{"type":16,"tag":29,"props":115,"children":116},{},[117],{"type":21,"value":118},"Save your recovery codes",{"type":21,"value":120}," somewhere safe (see below), then finish.",{"type":16,"tag":17,"props":122,"children":123},{},[124],{"type":21,"value":125},"From the next sign-in onwards, you'll be asked for a code from your app after entering your password.",{"type":16,"tag":127,"props":128,"children":129},"hint",{},[130],{"type":16,"tag":17,"props":131,"children":132},{},[133],{"type":21,"value":134},"Set up your authenticator app on a device you keep — not the same single device you might lose access to. A password manager that syncs across your devices is a good place to store TOTP secrets.",{"type":16,"tag":37,"props":136,"children":138},{"id":137},"recovery-codes",[139],{"type":21,"value":140},"Recovery codes",{"type":16,"tag":17,"props":142,"children":143},{},[144,146,151],{"type":21,"value":145},"When you enable MFA you are given a set of one-time ",{"type":16,"tag":29,"props":147,"children":148},{},[149],{"type":21,"value":150},"recovery codes",{"type":21,"value":152},". Each code lets you sign in once if you don't have your authenticator app — for example if your phone is lost, stolen or reset.",{"type":16,"tag":154,"props":155,"children":156},"ul",{},[157,169,181],{"type":16,"tag":66,"props":158,"children":159},{},[160,162,167],{"type":21,"value":161},"Store them in a password manager or another safe place, ",{"type":16,"tag":29,"props":163,"children":164},{},[165],{"type":21,"value":166},"not",{"type":21,"value":168}," only on the device that runs your authenticator app.",{"type":16,"tag":66,"props":170,"children":171},{},[172,174,179],{"type":21,"value":173},"Each recovery code works ",{"type":16,"tag":29,"props":175,"children":176},{},[177],{"type":21,"value":178},"once",{"type":21,"value":180},". After you use one, cross it off.",{"type":16,"tag":66,"props":182,"children":183},{},[184],{"type":21,"value":185},"You can regenerate a fresh set from the Security section at any time — doing so invalidates the old codes.",{"type":16,"tag":17,"props":187,"children":188},{},[189,191,196,198,205,210],{"type":21,"value":190},"If you run out of recovery codes ",{"type":16,"tag":29,"props":192,"children":193},{},[194],{"type":21,"value":195},"and",{"type":21,"value":197}," lose access to your authenticator app, contact ",{"type":16,"tag":72,"props":199,"children":204},{"href":200,"className":201,"rel":203},"mailto:info@webhookrelay.com",[202],"nav-link",[76],[],{"type":16,"tag":72,"props":206,"children":207},{"href":200},[208],{"type":21,"value":209},"info@webhookrelay.com",{"type":21,"value":211}," from the email address on the account so we can verify ownership and help you regain access.",{"type":16,"tag":37,"props":213,"children":215},{"id":214},"disable-mfa",[216],{"type":21,"value":217},"Disable MFA",{"type":16,"tag":17,"props":219,"children":220},{},[221,223,227,229,234],{"type":21,"value":222},"To turn MFA off, open the ",{"type":16,"tag":29,"props":224,"children":225},{},[226],{"type":21,"value":86},{"type":21,"value":228}," section of your ",{"type":16,"tag":72,"props":230,"children":232},{"href":74,"rel":231},[76],[233],{"type":21,"value":79},{"type":21,"value":235}," and disable two-factor authentication. You'll be asked to confirm with your password or a current code. We recommend keeping MFA enabled.",{"type":16,"tag":37,"props":237,"children":239},{"id":238},"mfa-and-teams",[240],{"type":21,"value":241},"MFA and teams",{"type":16,"tag":17,"props":243,"children":244},{},[245,247,253,255,260,262,268],{"type":21,"value":246},"If you invite ",{"type":16,"tag":72,"props":248,"children":250},{"href":249},"/docs/account/team",[251],{"type":21,"value":252},"team members or sub-accounts",{"type":21,"value":254},", each user enables MFA on ",{"type":16,"tag":29,"props":256,"children":257},{},[258],{"type":21,"value":259},"their own",{"type":21,"value":261}," login independently — protecting your account is up to every member who can access it. For organisation-wide enforcement and SSO (SAML with Okta, Active Directory and similar), see our ",{"type":16,"tag":72,"props":263,"children":265},{"href":264},"/pricing",[266],{"type":21,"value":267},"Enterprise plan",{"type":21,"value":269},".",{"type":16,"tag":37,"props":271,"children":273},{"id":272},"related",[274],{"type":21,"value":275},"Related",{"type":16,"tag":154,"props":277,"children":278},{},[279,288,296],{"type":16,"tag":66,"props":280,"children":281},{},[282],{"type":16,"tag":72,"props":283,"children":285},{"href":284},"/docs/account/account-management",[286],{"type":21,"value":287},"Account management",{"type":16,"tag":66,"props":289,"children":290},{},[291],{"type":16,"tag":72,"props":292,"children":293},{"href":249},[294],{"type":21,"value":295},"Teams and sub-accounts",{"type":16,"tag":66,"props":297,"children":298},{},[299],{"type":16,"tag":72,"props":300,"children":302},{"href":301},"/docs/security",[303],{"type":21,"value":304},"Security & technology overview",{"title":7,"searchDepth":306,"depth":306,"links":307},3,[308,310,311,312,313,314],{"id":39,"depth":309,"text":42},2,{"id":57,"depth":309,"text":60},{"id":137,"depth":309,"text":140},{"id":214,"depth":309,"text":217},{"id":238,"depth":309,"text":241},{"id":272,"depth":309,"text":275},"markdown","content:docs:account:2.mfa.md","content","docs/account/2.mfa.md","docs/account/2.mfa","md",{"loc":4},[323],{"_path":324,"title":325},"/docs/webhooks/internal/localhost","Receiving webhooks on localhost",[327,330,333,336,339,342,345,348],{"_path":328,"title":329},"/docs/installation/cli","CLI",{"_path":331,"title":332},"/docs/installation/docker","Docker container",{"_path":334,"title":335},"/docs/installation/docker-compose","Docker Compose",{"_path":337,"title":338},"/docs/installation/kubernetes","Kubernetes",{"_path":340,"title":341},"/docs/installation/autostart-windows","Autostart (Windows)",{"_path":343,"title":344},"/docs/installation/autostart-linux","Autostart (Linux)",{"_path":346,"title":347},"/docs/installation/autostart-macos","Autostart (MacOS)",{"_path":349,"title":350},"/docs/installation/behind-proxy","HTTP proxy configuration",[352,355,358,361],{"_path":353,"title":354},"/docs/webhooks/auth/username-password","Username and password",{"_path":356,"title":357},"/docs/webhooks/auth/hmac","HMAC",{"_path":359,"title":360},"/docs/webhooks/auth/jwt","JWT authentication",{"_path":362,"title":363},"/docs/webhooks/auth/http-method","Auth using request method",[365,368],{"_path":366,"title":367},"/docs/webhooks/public/public-destination","Forward to public URL",{"_path":369,"title":370},"/docs/webhooks/public/multiple-destination-urls","Multiple destinations",[372],{"_path":373,"title":374},"/docs/webhooks/cron/using-cron-webhooks","Schedule recurring webhooks",[376,379,382,385,388,391,394],{"_path":377,"title":378},"/docs/service-connections","Service Connections",{"_path":380,"title":381},"/docs/service-connections/aws_s3","AWS S3",{"_path":383,"title":384},"/docs/service-connections/aws_sns","AWS SNS",{"_path":386,"title":387},"/docs/service-connections/aws_sqs","AWS SQS",{"_path":389,"title":390},"/docs/service-connections/azure","Azure",{"_path":392,"title":393},"/docs/service-connections/gcp_gcs","GCP Cloud Storage",{"_path":395,"title":396},"/docs/service-connections/gcp_pubsub","GCP Pub/Sub",[398,401],{"_path":399,"title":400},"/docs/tunnels/demoing-your-website","Demoing your website",{"_path":402,"title":403},"/docs/tunnels/regions","Regions",[405,408,411,414],{"_path":406,"title":407},"/docs/email","Receive emails as webhooks",{"_path":409,"title":410},"/docs/email/payload","Email webhook payload",{"_path":412,"title":413},"/docs/email/filtering-and-policy","Sender filtering & policy",{"_path":415,"title":416},"/docs/email/cli","Create & poll email addresses from the CLI",[418,419,420,421],{"_path":284,"title":287},{"_path":4,"title":8},{"_path":249,"title":295},{"_path":422,"title":423},"/docs/account/billing-and-subscriptions","Billing & subscriptions",[425,428,431],{"_path":426,"title":427},"/docs/tutorials/n8n/email-trigger","n8n Email Trigger (Inbound Email)",{"_path":429,"title":430},"/docs/tutorials/n8n/webhook-trigger","n8n Webhook Trigger (No Public IP)",{"_path":432,"title":433},"/docs/tutorials/n8n/whatsapp-cloud-api-webhook","n8n WhatsApp Cloud API Webhook Setup",[435,438,441,444,447,450,453],{"_path":436,"title":437},"/docs/tutorials/cicd/jenkins-bitbucket","Jenkins and Bitbucket",{"_path":439,"title":440},"/docs/tutorials/cicd/jenkins-github","Jenkins and GitHub",{"_path":442,"title":443},"/docs/tutorials/cicd/jenkins-plugin","Jenkins Plugin",{"_path":445,"title":446},"/docs/tutorials/cicd/jenkins-plugin-multibranch","Jenkins Multibranch Pipelines",{"_path":448,"title":449},"/docs/tutorials/cicd/kubernetes-operator","Kubernetes Operator",{"_path":451,"title":452},"/docs/tutorials/cicd/terraform-atlantis","Terraform Atlantis",{"_path":454,"title":455},"/docs/tutorials/cicd/webhook-exec","Execute scripts on webhook",[457,460,463,466,469,472,475,478],{"_path":458,"title":459},"/docs/tutorials/email/airtable","Email to Airtable",{"_path":461,"title":462},"/docs/tutorials/email/api","Email to API",{"_path":464,"title":465},"/docs/tutorials/email/database","Email to Database",{"_path":467,"title":468},"/docs/tutorials/email/discord","Email to Discord",{"_path":470,"title":471},"/docs/tutorials/email/google-sheets","Email to Google Sheets",{"_path":473,"title":474},"/docs/tutorials/email/microsoft-teams","Email to Microsoft Teams",{"_path":476,"title":477},"/docs/tutorials/email/notion","Email to Notion",{"_path":479,"title":480},"/docs/tutorials/email/slack","Email to Slack",[482,485,488],{"_path":483,"title":484},"/docs/tutorials/edge/home-assistant","Home Assistant",{"_path":486,"title":487},"/docs/tutorials/edge/javascript-app","JavaScript app",{"_path":489,"title":490},"/docs/tutorials/edge/node-red","Node-RED",[492],{"_path":493,"title":494},"/docs/tutorials/warehouse/bigquery","GCP BigQuery",[496,499],{"_path":497,"title":498},"/docs/tutorials/transform/docker-to-slack","DockerHub webhook to Slack notification",{"_path":500,"title":501},"/docs/tutorials/transform/enrich-webhooks","Enrich webhooks from APIs",[503,506,509,512,515,518,521,524,527,530,532,535,538,541],{"_path":504,"title":505},"/docs/webhooks/functions/manipulating-json","JSON encoding",{"_path":507,"title":508},"/docs/webhooks/functions/make-http-request","Make HTTP request",{"_path":510,"title":511},"/docs/webhooks/functions/modify-request","Read, write request data",{"_path":513,"title":514},"/docs/webhooks/functions/multipart-form-data","Multipart form to JSON",{"_path":516,"title":517},"/docs/webhooks/functions/url-encoded-data","URL Encoded Form",{"_path":519,"title":520},"/docs/webhooks/functions/working-with-time","Working with time",{"_path":522,"title":523},"/docs/webhooks/functions/send-emails","Sending emails",{"_path":525,"title":526},"/docs/webhooks/functions/crypto-functions","Base64, encryption",{"_path":528,"title":529},"/docs/webhooks/functions/integrate-into-cicd","Integrating into CI/CD",{"_path":531,"title":494},"/docs/webhooks/functions/big-query",{"_path":533,"title":534},"/docs/webhooks/functions/accessing-metadata","Accessing metadata",{"_path":536,"title":537},"/docs/webhooks/functions/response-functions","Response (post-delivery) functions",{"_path":539,"title":540},"/docs/webhooks/functions/alerting","Alerting from functions",{"_path":542,"title":543},"/docs/webhooks/functions","Functions",1784458868644]