Verified workflow guide: Explains how users should treat additional authentication factors and recovery credentials.
1. Overview & Purpose
BursaPay includes authentication hardening such as MFA/2FA and recovery-code workflows in the security layer.
2. What You Need
An authenticated account and access to the supported security settings are required.
3. Step-by-Step Workflow
- Enable the supported MFA/2FA method.
- Store recovery credentials securely.
- Never share authentication secrets with support staff.
- Use the supported recovery flow if a factor is lost.
4. Rules, Boundaries & Troubleshooting
Support should never request a user's password, OTP, recovery code or secret key. Account recovery must remain within the designed authentication flow.
5. Verification & Next Steps
After recovery, re-check active sessions and authentication settings before resuming sensitive operations.