Account
Two-factor authentication
Enrolling an authenticator app, recovery codes, which roles must enroll, the fifteen-minute freshness rule for consequential actions, and what to do if you lose your device.
Last revised
MapProtector’s second factor is a time-based one-time code from an authenticator app — the six digits that change every thirty seconds. There is no SMS and no email code. It is required for every Brand Admin and for anyone who reads Amazon-sourced data, and it is asked for again, fresh, before the actions whose consequences reach a third party.
Enrolling
- Open Workspace › Settings › Security, or follow the prompt when your role requires it at sign-in.
- Scan the QR code with an authenticator app (any app that supports the standard: Google Authenticator, Microsoft Authenticator, 1Password, Authy and others), or enter the key by hand.
- Enter the six-digit code the app shows to confirm the enrollment.
- Save the ten recovery codes shown once. Each works once, in place of a code, if you lose the app. MapProtector keeps only a hash of them and cannot show them again; you can generate a new set from Security settings, which retires the old ones.
- Confirm that you have saved them. The workspace opens.
Signing in
After your password, enter the current code from the app. A recovery code works in the same field, once. A wrong code, an expired code and a used recovery code are refused with the same message, and attempts are rate-limited.
Fresh second factor for consequential actions
Some actions require that your second factor was presented within the last fifteen minutes: approving a notice, queueing and sending one, sealing an evidence package, configuring the sender identity, publishing a template or sequence version, and connecting Amazon. If yours is older, you are taken to a step-up challenge, and returned to exactly where you were. The challenge performs nothing; the action you then confirm is the decision.
Replacing your authenticator
From Security settings, choose to replace your authenticator. The new enrollment replaces the old one when it is confirmed, and a new set of recovery codes is issued.
If you lose your device
- Sign in with a recovery code, then enroll a new authenticator from Security settings.
- If you have no recovery codes either, ask a Brand Admin in your workspace to contact support. Your identity is confirmed out of band; nobody at MapProtector can read or reset your second factor from a screen.
What is stored
Your password is stored as an Argon2id hash. The authenticator secret is stored encrypted under a key held separately from the database. Recovery codes and session tokens are stored as SHA-256 digests. Changing your password ends every other session on the account.