1. Go to co:brand website
Log in or create a new account
2. A QR code will appear
This code contains a secret key used to generate time-based one-time passwords (TOTP)
3. Open your authenticator app
Launch Apple Passwords, Google Authenticator, Microsoft Authenticator, Authy on your phone
4. Tap to add a new account
Look for a “+” icon or “Add account” (on Apple Passwords, click ‘Codes’)
Select “Scan a QR code”
5. Scan the QR code
Point your phone’s camera at the QR code in Cobrand
The app will automatically save the code and start showing 6-digit passcodes
6. Enter the 6-digit code into the website
Go back to the site you’re setting up MFA on
Enter the first 6-digit code shown in your app to verify
Using Apple Passwords as an example, if you open that app and go to Codes (Passkeys for Google) you'll see Cobrand and can grab the one-time code.
MFA is now enabled
Each time you log in, you’ll enter your password plus a code from your authenticator app
The code changes every 30 seconds
Why am I seeing an “invalid code” error?
If the code you’re entering is marked as invalid but matches the code shown in your authenticator app, your device’s time may be out of sync.
Start by closing the authenticator app and restarting your phone. If the issue persists, check your device’s time settings and ensure they are set to update automatically:
Android
Open Settings
Tap System → Date & time
Enable:
Set time automatically
Set time zone automatically
iPhone
Open Settings
Tap General → Date & Time
Turn on Set Automatically