Skip to main content

Dashboard Setup

  1. Go to the Security page.
  2. In the Account MFA section, enable your desired methods (TOTP and/or Passkeys).
  3. (Optional) Toggle “Require at onboarding” to force MFA setup during signup.
  4. (Optional) Toggle “Session-based MFA” to require MFA for every new session.

Your UI SDK Implementation

  • Register device: registerTotpMfaDevice() returns a QR uri and secret.
  • Authenticate: authenticateTotpMfaDevice({ code }) completes the challenge.
  • Manage devices: getMfaDevices() lists devices; deleteMfaDevice() deletes.
  • Recovery codes: getMfaRecoveryCodes() to display; createNewMfaRecoveryCodes() to rotate; authenticateMfaRecoveryCode({ code }) to unblock login.
import { registerTotpMfaDevice, authenticateTotpMfaDevice, getMfaDevices } from '@dynamic-labs-sdk/client';

const register = async () => {
  const { uri } = await registerTotpMfaDevice();
  // Render QR code from `uri`
};

const verify = async (code) => {
  await authenticateTotpMfaDevice({ code });
};

const listDevices = async () => {
  const devices = await getMfaDevices();
  console.log(devices);
};
import {
  getMfaRecoveryCodes,
  createNewMfaRecoveryCodes,
  authenticateMfaRecoveryCode,
} from '@dynamic-labs-sdk/client';

const showCodes = async () => {
  const { recoveryCodes } = await getMfaRecoveryCodes();
  console.log(recoveryCodes);
};

const rotateCodes = async () => {
  const { recoveryCodes } = await createNewMfaRecoveryCodes();
  console.log(recoveryCodes);
};

const authWithRecovery = async (code) => {
  await authenticateMfaRecoveryCode({ code });
};
import { authenticateTotpMfaDevice, deleteMfaDevice } from '@dynamic-labs-sdk/client';

const deleteTotpDevice = async (deviceId, code) => {
  // Create a single-use MFA token using the device to be deleted
  await authenticateTotpMfaDevice({
    code,
    createMfaTokenOptions: { singleUse: true },
  });

  // Use the MFA token from the client to authorize deletion
  const mfaToken = dynamicClient.mfaToken;
  await deleteMfaDevice({ deviceId, mfaAuthToken: mfaToken });
};