Two-factor is enforced on sensitive builder accounts; recovery codes are the backup path.
Enter the 6-digit code from your authenticator app for [email protected].
Lost your device? Use a recovery code
The second step of sign-in when two-factor is on: enter the 6-digit code from your authenticator app. Lost the device? A one-time recovery code (from when you set up two-factor) gets you in instead — each recovery code works exactly once.
sp_Auth_ConsumeMfaRecoveryCode; success issues the full session via sp_Auth_RegisterSession.Implement this scaffold from the structured contract, then remove hard-coded preview rows. The source of truth is CLI Handoff and admin-cli-manifest.json.
Server-inject identity and scope values; never trust browser-supplied account, app, tenant, user, entitlement, price, or permission identifiers. Preserve the loading, empty, forbidden, failed, retrying, and completed states shown by the preview.