MFA Enhancements — Device Remember & SMS Backup

Overview

Two-factor authentication (also called MFA) adds a second step to logging in, so that a password alone is not enough to access your account. On Horsify it protects organisation administrators: if you are an admin of an organisation, you're asked for a second step when you log in. It isn't offered for other accounts at the moment.

This guide covers three things:

  1. Setting up MFA with an authenticator app or SMS.
  2. Using "Remember this device for 28 days" so you don't have to enter a code every time you log in from your own computer.
  3. Saving and using your recovery codes.

Setting Up MFA (First Time)

Setup happens when you log in: the first time an organisation administrator logs in without MFA configured, Horsify takes you to the setup page automatically. Choose one of the two methods below.

Option 1: Authenticator App (recommended)

An authenticator app generates a fresh 6-digit code every 30 seconds. Free apps include Google Authenticator, Microsoft Authenticator, and Authy.

  1. On the setup page, choose Authenticator App.
  2. Scan the QR code with your authenticator app, or type the shown key into the app manually.
  3. Your app will start showing a 6-digit code. Enter that code to confirm setup.

Option 2: SMS (backup)

You can receive your codes by text message instead.

  1. On the setup page, choose SMS.
  2. Enter your mobile number (for example, 0412 345 678).
  3. Horsify sends a 6-digit code by text. Enter it to confirm.
  4. If the code doesn't arrive, use the resend option. SMS codes are valid for 10 minutes, and you can request up to 10 messages per day.

You can set up SMS as a backup alongside an authenticator app, or use it on its own.

SMS works with Australian and New Zealand mobile numbers. A number typed without a country code is read for the country on your Horsify account, so a New Zealand rider can enter 021 123 4567 as it is. If your mobile is from the other country, start it with the country code: +64 for a New Zealand mobile, or +61 for an Australian one. The authenticator app is still the better choice, because it works from any country and needs no phone signal at all.

Save Your Recovery Codes

After your method is confirmed, Horsify shows a set of 10 recovery codes. These are single-use codes that let you get into your account if you lose access to your phone.

  • Write them down or store them somewhere safe (a password manager is ideal).
  • Each code works only once.
  • You must tick the box confirming you have saved them before you can finish.

Setup is now complete and you are logged in.

Logging In with MFA

  1. Enter your email and password as usual.
  2. If this device is already remembered, you go straight in — no code needed.
  3. Otherwise, you are asked for a verification code. You can:
    • Enter the code from your authenticator app, or
    • Switch to the SMS option and request a text code, or
    • Enter one of your recovery codes.
  4. Tick "Remember this device for 28 days" if you'd like to skip the code next time (see below).
  5. Confirm to finish logging in.

Remember This Device for 28 Days

When you enter a verification code, you'll see a "Remember this device for 28 days" checkbox. Tick it to tell Horsify this browser is trusted.

  • For the next 28 days, logging in from the same browser on the same device won't ask for an MFA code.
  • This trust is tied to that specific browser. Logging in from a different device, or a different browser, will still ask for a code.
  • The trust stays in place even after you log out — it applies to the device, not the session. After 28 days it expires and you'll be asked for a code again.

Only tick this on a device that is genuinely yours. Don't use it on a shared or public computer.

Managing Your MFA

Under Account & security → Security Settings you can see your MFA status and, if you use an authenticator app, generate a fresh set of recovery codes. Organisation administrators can't remove or replace their authenticator app themselves, because MFA is a required protection for accounts that manage an organisation — contact Horsify support if you need to change it, for example after getting a new phone.

There is no list of remembered devices to manage: each one simply stops being trusted after 28 days.

Troubleshooting

  • My authenticator code is rejected. Codes are time-based — make sure your phone's clock is set to update automatically. Wait for a fresh code and try again.
  • My SMS code didn't arrive. Check you entered the right mobile number, wait a moment, and use resend. There's a limit of 10 texts per day.
  • My mobile number is rejected. Check it's a mobile, not a landline. If it's from a different country to the one on your account, add the country code (+61 for Australia, +64 for New Zealand). If it still won't save, set up an authenticator app instead.
  • I've lost my phone. Log in using one of your recovery codes, then contact Horsify support to have your authenticator app reset so you can set up the new phone.
  • I've run out of recovery codes. Once logged in, generate a new set under Account & security → Security Settings. Generating new codes replaces the old set.

Related Features

Horse Health Declarations - User Guide
Password Reset Guide