Skip to content
Glossary

What is multi-factor authentication (MFA)?

The single most effective control against stolen passwords, and one of the first questions on a security review.

Plutonapps Engineering1 min read

In short

Multi-factor authentication (MFA) requires two or more different kinds of proof before someone can sign in: something they know, such as a password; something they have, such as a phone or security key; or something they are, such as a fingerprint. A stolen password alone is then not enough.

Also called: MFA, Two-factor authentication, 2FA

Why it matters when your prototype goes to production

Your users reuse passwords, and some of those passwords are already in leaked lists. MFA is what stops a reused password from becoming a breached account. For your own team, it matters even more: an admin account or a database dashboard without MFA is the easiest way into everything.

Where to require it first

  1. Every account your team uses to run the product: hosting, database, code repository, email, payments.
  2. Admin roles inside your own app.
  3. Customer accounts that hold money, health or other sensitive data, then everyone else as an option.

Auth providers such as Clerk offer MFA as a setting, so for your users it is mostly a product decision. For your team's accounts it is a checklist, and security reviews will ask to see it done.

Common questions

What is the difference between MFA and 2FA?

2FA uses exactly two factors. MFA means two or more. In everyday use the terms are often interchangeable.

Can MFA be bypassed?

Weaker forms can, for example SMS codes through SIM swapping or phishing pages that relay codes. Authenticator apps, passkeys and security keys are much harder to defeat.

More on this: Production architecture & security · All glossary terms

Built something in Lovable you want people to rely on?

We are the engineers who take it the rest of the way — secured, tested, released and supported.