@php $methodsByProvider = collect($authMethods)->keyBy('provider'); $hasTotp = $methodsByProvider->has('totp') && $methodsByProvider->get('totp')?->verified_at; $hasEmail = ($user->two_factor ?? false) || ($methodsByProvider->has('email') && $methodsByProvider->get('email')?->verified_at); $channelProviders = ['sms', 'whatsapp', 'telegram']; $profileMfaVerification = session('profile_mfa_verification'); @endphp

Multi-factor authentication

Add a second factor to protect your account from unauthorized access.

{{-- Authenticator (TOTP) --}}
Authenticator app

Use Google Authenticator, Authy, or a compatible TOTP app.

@if($hasTotp) Enabled @elseif(!empty($mfaSettings['authenticator'])) Available @else Disabled by org @endif
@if($hasTotp)
@csrf
@elseif(!empty($mfaSettings['authenticator'])) @if($pendingTotpSecret)

Scan this QR code with your authenticator app:

Alternatively, enter this setup key manually:

{{ $pendingTotpSecret }}
Advanced setup URI {{ $pendingTotpQrUrl }}
@csrf
@else
@csrf
@endif @endif
{{-- Email OTP --}}
Email OTP

Receive one-time codes at {{ $user->email }}.

@if($hasEmail) Enabled @elseif(!empty($mfaSettings['email'])) Available @else Disabled by org @endif
@if($hasEmail)
@csrf
@elseif(!empty($mfaSettings['email']))
@csrf
@endif
{{-- Channel linker --}}
@if(is_array($profileMfaVerification))
Verify {{ ucfirst($profileMfaVerification['provider']) }} OTP

Enter the code sent to {{ $profileMfaVerification['identifier'] }}.

@csrf
@endif
Link OTP channel

Connect SMS, WhatsApp, or Telegram if your organization allows them.

@php $linkedChannels = collect($authMethods)->whereIn('provider', $channelProviders); @endphp @if($linkedChannels->isNotEmpty())
@foreach($linkedChannels as $method) @endforeach
Provider Identifier Status
{{ $method->provider }} {{ $method->identifier }} @if($method->verified_at) Verified @else Unverified @endif
@csrf
@endif @php $anyChannelEnabled = !empty($mfaSettings['sms']) || !empty($mfaSettings['whatsapp']) || !empty($mfaSettings['telegram']); @endphp @if($anyChannelEnabled)
@csrf
@else

No OTP channels are enabled by your organization.

@endif
@if($pendingTotpSecret) @push('scripts') @endpush @endif