Skip to Content
For end-usersSetting up MFA

Setting up Multi-Factor Authentication

Pair your account with an authenticator app so sign-in needs both your password / email link and a rotating 6-digit code.

Who this is for: any account, but especially admins and anyone who edits sensitive data (volunteers, requesters, campaigns).

Steps

  1. Install an authenticator on your phone if you don’t have one: Google Authenticator, 1Password, Authy, or a built-in OS one all work.
  2. Sign in to CartonCrew. On first sign-in the Set up MFA page is mandatory.
  3. CartonCrew shows a QR code. Open your authenticator app, Add account, and scan the QR.
  4. The app starts showing a 6-digit code that changes every 30 seconds. Type the current one into CartonCrew.
  5. Save the recovery code CartonCrew shows you (one-off use, only displayed once). Print it or store it in a password manager — losing it means an admin has to reset your MFA.

What you’ll see

Video — coming soonSet up MFA at first loginRecorder brief: V6 — MFA enrollment. Show the QR, the authenticator scan, the 6-digit entry, then the recovery-code screen with a callout to save it.

From that point on, every new sign-in asks for the rotating 6-digit code.

Common issues

  • “Invalid code” — the code changed mid-entry. Wait for a fresh one and try again. If it keeps failing, your phone’s clock is out of sync; turn on automatic time.
  • Lost your phone / authenticator — use the recovery code you saved at setup. If you didn’t save it, an org Owner can reset your MFA from Settings → Users → your row → Reset MFA.
  • Want to change authenticator apps — remove the entry in the old app, then ask an admin to reset your MFA so you re-enroll.

Last updated: 2026-06-01 · Applies to: CartonCrew v1.54+