2-Factor Authentication
HauntedMC supports email-based multi-factor authentication for website accounts.
How it works
- Sign in with your password.
- Enter the short-lived verification code sent to the email address on your account.
- After the code is verified, the session is unlocked.
Codes expire automatically and are single-use. If your request context changes, for example because your IP address changes, the session can be ended and you will need to verify again.
Enabling MFA
Open Account > Security and enable email-based 2-factor authentication. A verification code will be sent to your account email address to confirm the setup.
Required MFA
Some account roles require MFA before the account can be used. The built-in ADMIN role is configured that way by default. If MFA is required and not configured yet, HauntedMC will guide you through setup after your password is verified.
Recovery guidance
- Keep access to the mailbox attached to your account.
- If a code expires, request a new one instead of reusing an older email.
- If you did not request a code, ignore the message and change your password.