Settings
Multi-Factor Authentication
Set up multi-factor authentication (MFA) to add an extra layer of security to your PetroBench account.
Multi-factor authentication (MFA) requires a second verification step when you sign in, protecting your account even if your password is compromised.
PetroBench supports authenticator apps that generate time-based one-time passwords (TOTP). If you don't already have one, download any of the following:
- Google Authenticator - iOS · Android
- Microsoft Authenticator - iOS · Android
- Authy - iOS · Android
- 1Password - iOS · Android
Enable MFA
Open security settings
Go to Settings > Security and click Enable MFA.
Scan the QR code
Open your authenticator app and scan the QR code displayed on screen. If you can't scan, click Can't scan? to reveal the setup key and enter it manually.
Save the setup key somewhere secure. You'll need it if you switch phones or lose access to your authenticator app.
Enter the verification code
Type the 6-digit code from your authenticator app and click Verify.
Save your recovery codes
PetroBench generates a set of one-time recovery codes. Download or copy these codes and store them in a safe place.
Each recovery code can only be used once. If you lose both your authenticator app and your recovery codes, you'll need to contact support to regain access.
MFA is now active. You'll be prompted for a code each time you sign in.
Sign In with MFA
- Enter your email and password as usual
- When prompted, open your authenticator app
- Enter the current 6-digit code
- Click Log In
Codes refresh every 30 seconds. If a code expires before you submit it, wait for the next one.
Use a Recovery Code
If you don't have access to your authenticator app:
- On the MFA verification screen, click Use a recovery code
- Enter one of your saved recovery codes
- Click Verify
Recovery codes are single-use. After signing in, set up MFA again on a new device or generate new recovery codes from Settings > Security.
Disable MFA
- Go to Settings > Security
- Click Disable MFA
- Enter your password to confirm
- Enter a code from your authenticator app
- Click Confirm
Regenerate Recovery Codes
If you've used most of your recovery codes or suspect they've been compromised:
- Go to Settings > Security
- Click Regenerate Recovery Codes
- Enter your password and a current MFA code
- Save the new codes - previous codes are immediately invalidated
Organization-Enforced MFA
Organization admins can require MFA for all members. When enforced:
- Users without MFA are prompted to set it up at next sign-in
- MFA cannot be disabled while the requirement is active
- Admins manage this setting from Organization Settings > Security
If your organization enforces MFA, you won't see the option to disable it in your personal security settings.