Step-by-step login flow for existing OnyxOS Developer Portal users, including MFA verification via SMS or TOTP authenticator app.

Existing User Login Flow

When an existing user logs in, the system checks the MFA status on their account and directs them through one of two paths.

Step 1: Login Page

Navigate to the Login page, enter your username or email and password, solve the CAPTCHA, and click Login. If your credentials are incorrect, an error is displayed. If credentials are valid, the system checks your MFA status.

Step 2: MFA Status Check

  • If MFA is not yet set up, you are directed through Path A to complete MFA setup.
  • If MFA is already configured, you are directed through Path B to verify your identity.

Path A — MFA Not Yet Set Up

Step 3: Set Up Two-Factor Authentication

A Set Up Two-Factor Authentication modal appears. It displays your phone number on file (masked, e.g. (***) ***-6053) and prompts you to confirm or enter a different number. Click Send Verification Code to send an OTP to the displayed number.

Step 4: Enter OTP and Enable MFA

Enter the 6-digit code and click Verify & Enable MFA. MFA is now fully configured. You may also click Change number to use a different phone, or Resend Code once the timer expires.

Step 5: Dashboard

After MFA is enabled, you are redirected to the Dashboard. All future logins will follow Path B.

Path B — MFA Already Configured

Step 3: Choose Verification Method

A Choose Verification Method modal appears with two options: SMS and TOTP. SMS sends a one-time code to your registered phone. TOTP uses a code from your authenticator app (available only if you have enrolled a TOTP device).

Step 4: OTP Verification

  • If you selected SMS: enter the OTP received via SMS and click Verify. If valid, you are redirected to the Dashboard.
  • If you selected TOTP: see the Logging In with TOTP section below.

Step 5: Dashboard Access

Once the OTP or TOTP code is confirmed, a session is created and you are granted full access to the Dashboard.


Authenticator App (TOTP)

TOTP (Time-based One-Time Password) is an optional second-factor method that generates 6-digit codes via a compatible authenticator app such as Google Authenticator, Authy, or Microsoft Authenticator. Once enrolled, you can choose TOTP instead of SMS at login. SMS MFA remains available as a backup at all times.

Note: SMS MFA must already be enabled on your account before you can enroll a TOTP device. If SMS MFA is not active, the Authenticator App card on your profile will appear locked and the Enable button will be disabled.

Logging In with TOTP

Step 1: Username and Password

Navigate to the Login page, enter your credentials, complete the CAPTCHA, and click Login.

Step 2: Choose Verification Method

A Choose Verification Method modal appears. Click TOTP to proceed. Selecting TOTP skips the SMS step entirely — no code is sent over SMS.

Step 3: Enter 6-Digit Code from Authenticator App

Open your authenticator app and enter the current 6-digit code for this account. Click Verify. If the code is invalid, the page shows an error and you may try again.

Step 4: Login Completed

Once the portal confirms the code, you are redirected to the Dashboard.

Removing the Authenticator App

Step 1: Click “Remove”

Log in and navigate to your Profile or Account Settings page. On the Authenticator App card, click the Remove button. An inline confirmation panel appears with Yes, remove it and Cancel buttons.

Step 2: Confirm Removal

Click Yes, remove it. The portal sends a delete request to remove the TOTP factor.

Step 3: Card Resets to “Not Set Up”

The Authenticator App card reverts to the Not set up state. Your account remains protected by SMS MFA. You can re-enroll a TOTP device at any time by clicking Enable again.