What is multi-factor authentication (MFA)?
The single most effective control against stolen passwords, and one of the first questions on a security review.
In short
Multi-factor authentication (MFA) requires two or more different kinds of proof before someone can sign in: something they know, such as a password; something they have, such as a phone or security key; or something they are, such as a fingerprint. A stolen password alone is then not enough.
Also called: MFA, Two-factor authentication, 2FA
Why it matters when your prototype goes to production
Your users reuse passwords, and some of those passwords are already in leaked lists. MFA is what stops a reused password from becoming a breached account. For your own team, it matters even more: an admin account or a database dashboard without MFA is the easiest way into everything.
Where to require it first
- Every account your team uses to run the product: hosting, database, code repository, email, payments.
- Admin roles inside your own app.
- Customer accounts that hold money, health or other sensitive data, then everyone else as an option.
Auth providers such as Clerk offer MFA as a setting, so for your users it is mostly a product decision. For your team's accounts it is a checklist, and security reviews will ask to see it done.
Common questions
What is the difference between MFA and 2FA?
2FA uses exactly two factors. MFA means two or more. In everyday use the terms are often interchangeable.
Can MFA be bypassed?
Weaker forms can, for example SMS codes through SIM swapping or phishing pages that relay codes. Authenticator apps, passkeys and security keys are much harder to defeat.
Related terms
Sources
More on this: Production architecture & security · All glossary terms
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.