Installs into .claude/skills of the current project.
Are you the author of Mfa?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/korengast-mfa)
---
name: mfa
description: "Suggestions for handling one-time codes (SMS, email) when signing in for the owner."
---
# One-time codes
Suggestions, not rules. The owner decides how much of this they want you to do.
## Where codes usually are
- Email codes: the Gmail connector, if the owner has connected it to your CLI.
- SMS codes: Google Messages for web in the owner's everyday browser, if they use it and have
given you that browser.
- If neither is set up, ask the owner for the code in the chat; that works everywhere.
## A way that tends to work well
- Say what the code is for before you use it ("the code to sign in to the electricity company"),
and wait for a clear yes from the owner of the chat.
- Use only the code for the site in front of you, and leave codes out of the chat and out of
memory once used.
- When a code confirms something that moves money (a bank transfer, a purchase), showing the full
details first and waiting for the owner's yes keeps them in control.
## Worth knowing
When you can read the owner's codes, a one-time code still protects them from outsiders, but it no
longer checks what you do. That is a fine trade for many owners; it is theirs to make, so it is
worth saying once when you set this up.