MFA & Security
Enable two-factor authentication, manage sessions, and review security events.
Last updated August 31, 2026
Protect your AEO Goal account with two-factor authentication (2FA/MFA) and manage active sessions.
Enabling two-factor authentication
- Go to Settings → Security.
- Click Enable two-factor authentication.
- Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, etc.).
- Enter the 6-digit code to confirm.
- Save your backup codes - store them somewhere secure.
Once enabled, every login requires your password plus a 6-digit TOTP code.
Managing active sessions
Settings → Security → Active sessions shows all devices currently logged in. Click Revoke next to any session to sign it out immediately.
Sign out all other sessions revokes every session except your current one.
Security log
Settings → Security → Security log shows a timestamped history of:
- Logins (successful and failed)
- 2FA events
- Password changes
- Session revocations
- API key creation and revocation
- Role changes
Changing your password
- Go to Settings → Security → Password.
- Enter your current password and a new password.
- Click Save.
All other sessions are revoked when you change your password.
Account recovery
If you lose access to your 2FA device, use one of the backup codes saved during setup. If you no longer have backup codes, contact support - recovery requires identity verification.