Vovy adds optional two-factor login using authenticator apps, with a QR code setup screen and a code check at sign in, using Supabase MFA.
Add two-factor authentication with Google Authenticator
How it works
- Explain how 2FA works: A card shows the flow: after the password, the user types a 6-digit code from an app like Google Authenticator or 1Password, which changes every 30 seconds.
- Build the setup screen: In Cursor Vovy adds a security settings page that calls mfa.enroll, shows the QR code, and verifies the first code.
- Ask for the code at login: It checks the user's assurance level after sign in, and if 2FA is on, shows a code screen that calls mfa.challengeAndVerify.
- Require 2FA for sensitive data: Vovy can add database policies that require aal2, the verified level, for tables like billing or admin data.
- Test with your phone: It enrolls your account, you scan the QR code, and Vovy logs in again to confirm the code is required.
What you provide
- A Supabase project with login working
- An authenticator app on your phone
What you get
- A 2FA setup page with QR code
- A code check at login
- Optional stricter database rules
- A tested enrollment
FAQ
Does Supabase charge for MFA?
Authenticator app (TOTP) MFA is included on all plans. Phone-based MFA is a paid add-on.
What if a user loses their phone?
Encourage enrolling a second factor. As an admin you can remove a user's factor so they can set it up again.
Should I force everyone to use 2FA?
Usually not for consumer apps. Make it optional, and require it for admins and high-risk actions.
Related tasks
All tasks