Security controls
Account sign-in and community access controls in mcord
mcord provides TOTP two-factor authentication with recovery codes, short-lived desktop QR login approved from a signed-in phone, and community roles and channel permissions for controlling access to shared spaces.
Add a second factor to account sign-in
Members can enable TOTP two-factor authentication and use codes from a compatible authenticator during sign-in. Recovery codes provide a separate recovery path and should be stored somewhere safe and separate from the signed-in device.
Two-factor authentication protects the sign-in flow with an additional proof; it does not replace careful password and device practices.
- Time-based one-time password authentication
- Recovery codes for account recovery planning
- Member-controlled activation in account security settings
Approve a short-lived desktop QR login from your phone
A signed-in phone can scan a short-lived QR challenge shown on a desktop login screen. The phone asks the member to approve the specific login, adding a deliberate confirmation step before the desktop session proceeds.
Members should compare the displayed confirmation information and approve only a device that is physically in front of them. An unexpected approval request should be rejected.
Control community spaces with roles and permissions
Roles can represent responsibilities or member groups, and channel permissions can determine who is allowed into particular text or voice spaces.
These are configuration tools rather than automatic guarantees. Community owners should review access as teams and responsibilities change, and bot operators should limit automation to its intended spaces.
FAQ
Questions and direct answers
Does mcord support authenticator-app 2FA?
Yes. mcord supports TOTP two-factor authentication and recovery codes.
How does mcord QR login work?
A signed-in phone scans a short-lived challenge from the desktop login page and the member explicitly approves that desktop login on the phone.
Should every QR login request be approved?
No. A member should approve only a login they started on a device physically in front of them and reject unexpected requests.
Can communities limit access to channels?
Yes. Roles and channel permissions can be configured to control access to particular community spaces.
MCORD · STAY CLOSE

