Skip to main content

Multi-Factor Authentication

Set Up MFA Using a QR Code & Passkey (TOTP)

1. Go to co:brand website

  • Log in or create a new account

2. A QR code will appear

  • This code contains a secret key used to generate time-based one-time passwords (TOTP)

3. Open your authenticator app

  • Launch Apple Passwords, Google Authenticator, Microsoft Authenticator, Authy on your phone

4. Tap to add a new account

  • Look for a “+” icon or “Add account” (on Apple Passwords, click ‘Codes’)

  • Select “Scan a QR code”

5. Scan the QR code

  • Point your phone’s camera at the QR code in Cobrand

  • The app will automatically save the code and start showing 6-digit passcodes

6. Enter the 6-digit code into the website

  • Go back to the site you’re setting up MFA on

  • Enter the first 6-digit code shown in your app to verify

  • Using Apple Passwords as an example, if you open that app and go to Codes (Passkeys for Google) you'll see Cobrand and can grab the one-time code.

MFA is now enabled

  • Each time you log in, you’ll enter your password plus a code from your authenticator app

  • The code changes every 30 seconds


Why am I seeing an “invalid code” error?

If the code you’re entering is marked as invalid but matches the code shown in your authenticator app, your device’s time may be out of sync.

Start by closing the authenticator app and restarting your phone. If the issue persists, check your device’s time settings and ensure they are set to update automatically:

Android

  1. Open Settings

  2. Tap SystemDate & time

  3. Enable:

    • Set time automatically

    • Set time zone automatically

iPhone

  1. Open Settings

  2. Tap GeneralDate & Time

  3. Turn on Set Automatically

Did this answer your question?