LuraFlow
PlatformPricingBlogDocs
Log inStart Free →
LuraFlow

AI-powered business operations platform for hosting and digital service businesses.

Product

  • Platform
  • Pricing
  • Early Access
  • Roadmap
  • Platform comparison

Resources

  • Documentation
  • API Reference
  • Changelog
  • Status Page
  • Community

Company

  • About Us
  • Blog
  • Contact
  • Migration

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DPA
  • Security

© 2026 LuraFlow Inc. All rights reserved.

Encryption in transit & at restPrivacy-first designhello@luraflow.com
Guides home
Getting started
  • Platform accounts and tenant workspaces
  • Choose a workspace at sign-in
  • Initial reseller setup sequence
  • Staff roles and access
  • View your LuraFlow plan and grant
  • Account security and MFA
  • Platform plan billing versus customer billing
Hosting and domains
  • Connect a WHM / cPanel server
  • Understand Test connection versus Save
  • Discover and map hosting packages
  • Hosting products and pricing
  • Hosting service lifecycle
  • Dedicated, VPS, and manual delivery
  • Connect Dynadot
  • TLD catalogue and sell prices
  • Domain search and registration
  • Transfers, renewals, lock, and auth codes
  • Nameservers and DNS
  • Domain search widgets
  • Domain order settings
  • Hosting and domain failure recovery
  • Subscriptions and cancellations
Brand and operations
  • Staff roles and access
  • Name, logo, and colours
  • Multiple brands and limits
  • Custom portal domain, DNS, and TLS
  • Support contact versus account email
  • Customer portal settings
  • Email sender and provider
  • Email templates, variables, and preview
  • Customer records
  • Support tickets
  • Notifications and automation
Billing and finance
  • View your LuraFlow plan and grant
  • Hosting products and pricing
  • Platform plan billing versus customer billing
  • Invoices and payments
  • Tax, coupons, and credits
  • Subscriptions and cancellations
  • Reports and export
  • Bookkeeping features that are not available
Marketing and growth
  • Social Hub workflow today
  • Planned Social Hub capabilities
API and integrations
  • Notifications and automation
  • API keys, webhooks, and safe examples
API overview
  1. Guides
  2. /getting-started
  3. /Account security and MFA

verified · reviewed 2026-09-12

Account security and MFA

Required TOTP is enforced before access and refresh tokens are issued.

Audience
tenant-admin, staff
Roles / plan
Each membership has its own password and MFA flags. All plans.
Menu
Dashboard → Settings → Security, or Manage security settings where offered

Prerequisites

  • An authenticator app

Google confirms the Google account. It does not satisfy LuraFlow TOTP. Password eligibility is per membership: a workspace without a local password cannot use password login for that row.

  1. Open Security settings for the membership you are using.
  2. Enrol TOTP and store recovery codes offline.
  3. Sign out and sign in again. If MFA is required, tokens appear only after a valid code.

Lockout

Repeated failures set lockedUntil on that user record. Wait out the lock or use a different eligible membership. Do not expect a new workspace to appear as a bypass.

Open this setting on luraflow.com — uses the safe login redirect. Never opens another tenant hostname.

Related guides

  • Choose a workspace at sign-in

Canonical: https://luraflow.com/docs/getting-started/account-security

On this page

  • Outcome
  • Steps
  • Related