MFA & Security

Enable two-factor authentication, manage sessions, and review security events.

Last updated August 31, 2026

Protect your AEO Goal account with two-factor authentication (2FA/MFA) and manage active sessions.

Enabling two-factor authentication

  1. Go to Settings → Security.
  2. Click Enable two-factor authentication.
  3. Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, etc.).
  4. Enter the 6-digit code to confirm.
  5. Save your backup codes - store them somewhere secure.

Once enabled, every login requires your password plus a 6-digit TOTP code.

Managing active sessions

Settings → Security → Active sessions shows all devices currently logged in. Click Revoke next to any session to sign it out immediately.

Sign out all other sessions revokes every session except your current one.

Security log

Settings → Security → Security log shows a timestamped history of:

  • Logins (successful and failed)
  • 2FA events
  • Password changes
  • Session revocations
  • API key creation and revocation
  • Role changes

Changing your password

  1. Go to Settings → Security → Password.
  2. Enter your current password and a new password.
  3. Click Save.

All other sessions are revoked when you change your password.

Account recovery

If you lose access to your 2FA device, use one of the backup codes saved during setup. If you no longer have backup codes, contact support - recovery requires identity verification.

Frequently asked questions

How do I enable two-factor authentication?

Go to Settings, Security, click Enable two-factor authentication, scan the QR code with an authenticator app such as Google Authenticator, Authy, or 1Password, enter the 6-digit code to confirm, and save your backup codes somewhere secure.

How do I sign out other devices?

Under Settings, Security, Active sessions you can see all devices currently logged in and click Revoke next to any session, or use Sign out all other sessions to revoke every session except your current one.

What does the security log show?

The security log at Settings, Security, Security log shows a timestamped history of logins, 2FA events, password changes, session revocations, API key creation and revocation, and role changes.

What can I do if I lose access to my 2FA device?

Use one of the backup codes saved during setup. If you no longer have backup codes, contact support, since recovery requires identity verification.