2FA
Authenticator-firstUse a real authenticator app and store recovery codes safely.
Account
Security in opheli.ai means protecting account access, provider credentials, attached context, and support boundaries. Two-factor authentication helps protect the account layer even if a password is exposed.
Guide summary
Protect your account, provider keys, and recovery posture with two-factor authentication and good credential hygiene.
Guide type
AccountThis guide reflects the current product workflow and surface ownership.
Sections
7Summary first, then steps, mistakes, and recovery notes.
Related guides
3Written against the current product structure and core execution workflow.
2FA
Authenticator-firstUse a real authenticator app and store recovery codes safely.
Provider keys
Encrypted at restThe product should not expose provider secrets back to the browser.
Related action
Review support boundariesSupport should not receive your credentials or hidden runtime secrets.
Guide section
Security and 2FA cover account access, credential posture, recovery options, and safe product behavior.
When to use it
Use it during account setup, after a security concern, or before connecting real provider credentials.
Where to find it
Find it in Security / 2FA, Provider Vault, and account settings.
What happens next
You use this surface as part of the broader mission -> task -> run -> artifact workflow.
Common mistake
Skipping recovery code storage
Related action
Open Contact Support only after removing secrets from the message body.
Guide section
Provider-backed execution and user-owned context deserve stronger access protection than a password alone.
Guide section
Security posture sits beneath every other product action. Weak access hygiene can compromise the whole execution environment.
Guide section
Guide section
Inputs needed
Authenticator app
Secure recovery-code storage
Clean provider credential hygiene
Outputs produced
Better account protection
Safer provider posture
Cleaner recovery path if a password is lost
Guide section
Guide section
If 2FA or recovery feels blocked, use the documented account recovery path rather than disabling security posture casually.