Overview
Voxworks protects your account with three separate, independent codes — they are not interchangeable and each serves a different purpose:- Multi-Factor Authentication (MFA) — an authenticator-app code you enrol yourself, checked every time you sign in.
- Mobile number verification — a one-off SMS code that confirms the mobile number on your profile is really yours.
- Email verification codes — 6-digit codes sent to your signed-in email address that gate destructive, irreversible actions like deleting an account.
Setting Up Multi-Factor Authentication (TOTP)
Voxworks supports authenticator-app factors — also known as TOTP (Time-based One-Time Password) — using apps like Google Authenticator, Authy or 1Password. To enrol a factor:- Click your profile picture in the sidebar and choose Personal Settings.
- Select the Multi-Factor tab in the left-hand menu.
- Click Setup a new Factor.
- Give the factor a memorable name (for example, “iPhone 14”) so you can identify it later, then continue.
- Scan the QR code with your authenticator app.
- Enter the 6-digit code your app generates — for example
482913— and click Enable Factor.
Signing In With Multi-Factor Authentication
Once you have at least one verified authenticator factor, Voxworks requires it on every sign-in — password sign-in, magic link or Google OAuth all lead to the same challenge if a factor is enrolled. After you complete your primary sign-in, the app checks whether your session has cleared multi-factor verification. If it hasn’t, you’re redirected to the verification page (/auth/verify):
- If you have more than one enrolled factor, you’re first asked to choose which one to use (“Choose a factor to verify your identity”), shown as a list of your factor names.
- If you have exactly one enrolled factor, it’s selected automatically and you go straight to the code entry step.
- Enter the current 6-digit code from your authenticator app (for example
118204). An incorrect code shows an “Invalid Verification Code” message and lets you try again. - On success you’re redirected to the page you were originally headed to.
Verifying Your Mobile Number (SMS)
Separately from sign-in, Voxworks verifies the mobile number on your profile the first time you set it — this is a one-off proof that the number is genuinely yours, not a recurring sign-in factor. This step runs during setup, right after you enter your personal details: Voxworks texts a 6-digit code to the number you entered and asks you to enter it before you continue. Key behaviour:- Australian mobile numbers only — accepted formats include
04XX XXX XXX,+61412345678and61412345678. Landline numbers and non-Australian numbers are rejected. - The code is a 6-digit numeric code, entered as six individual digit boxes; pasting a copied 6-digit code fills all the boxes at once.
- Resend cooldown: after a code is sent, Resend verification code is disabled for 60 seconds.
- Rate limit: no more than 3 codes per mobile number per rolling hour. If you exceed this, sending is blocked with a “Too many attempts. Please try again in an hour” message until the window resets.
- If you didn’t receive the code, the screen offers a support contact link as a fallback.
Email Verification Codes for Sensitive Actions
Some destructive, irreversible actions are gated behind a one-off email code rather than (or in addition to) your regular sign-in:- Deleting your personal account
- Deleting a team
- Transferring a team’s primary ownership to another member
Next Steps
- Signing Up, Signing In & Password Recovery — the primary sign-in methods that MFA and the
/auth/verifychallenge sit on top of. - Your Profile & Personal Settings — where your mobile number lives and why it matters beyond verification.
- Deleting an Account or Team — the full email-verification-gated deletion flows.
- Inviting & Managing Members — team ownership transfer and its email verification step.

