Two-factor authentication with TOTP for chauffeur platform accounts

Account hardening

2FA Authentication

TOTP authenticator apps and backup codes protect high-privilege chauffeur platform accounts.

Two-factor authentication with TOTP for chauffeur platform accounts
Overview

MFA coverage

Administrators enforce MFA org-wide; partners enable it for finance and dispatch leads.

Guests optionally protect accounts holding saved payment methods and passenger profiles.

Backup codes regenerate one-time recovery sets when travelers replace phones.

  • TOTP authenticator apps
  • One-time backup codes
  • Org enforcement policies
  • Recovery workflows
How it works

Adding a second factor

  • Step 1

    Scan

    Users scan QR codes into Google Authenticator, Authy, or compatible apps.

  • Step 2

    Verify

    A challenge code confirms the secret before MFA is marked active.

  • Step 3

    Recover

    Backup codes unlock access if devices are lost; admins can reset with audit.

Two-factor authentication with TOTP for chauffeur platform accounts
Benefits

Protection value

  • Credential stuffing defense

    Stolen passwords alone cannot access dispatch or payout screens.

  • Compliance alignment

    MFA satisfies common enterprise security questionnaire requirements.

  • Configurable enforcement

    Tenants stage rollout — optional for guests, mandatory for admins.

2FA Authentication security
Security

MFA security

Secrets encrypt at rest; lockout policies throttle brute-force OTP attempts.

Admin resets require super-admin approval and generate audit events.

  • Encrypted TOTP secrets
  • OTP attempt throttling
  • Admin reset approval
  • Audit on bypass
2FA Authentication integration
Integration

Auth integration

MFA integrates with JWT session issuance — step-up challenges appear after password or OAuth success.

Security settings panel in customer and partner portals manages enrollment.

  • Step-up JWT claims
  • Portal security settings
  • Backup code hashing
  • Org policy API
2FA Authentication business use cases
Use cases

MFA adopters

  • HQ administrators

    Global admins enforce MFA before accessing payout approvals.

  • Partner finance

    Controllers protect settlement exports behind authenticator challenges.

  • VIP guests

    High-net-worth travelers opt in to guard saved Amex profiles.

Support

2FA FAQ