Some upstream systems require multi-factor authentication (MFA) for the account used by an integration. MFA is a provider requirement, not a universal K16 integration setting.
Never paste an authenticator secret, upload an MFA QR code, or send a one-time code in a support
message. These values can grant access to the provider account.
Use the supported workflow
- Confirm that the provider requires MFA for the dedicated integration account.
- Ask the provider administrator whether automated access is supported for that account type.
- Open the integration’s provider settings in K16.
- Follow the provider-specific MFA controls only when they appear in your workspace.
- Select Validate draft or Revalidate now, depending on whether you are editing configuration or checking saved configuration.
- Confirm that provider sign-in and K16 validation both succeed.
The current integration editor does not expose one universal MFA control for every provider. If K16 reports an MFA requirement and the provider settings do not show an approved setup flow, stop and contact K16 Support.
When your provider form includes How to set up MFA, use that field to enroll the dedicated integration account:
- Open the upstream system’s authenticator setup for the integration account.
- In the K16 field, select Upload QR Image or enter the manual secret key supplied by the upstream system.
- Use the current verification code shown in K16 to complete enrollment in the upstream system.
- Validate the integration configuration, save it, and confirm the saved configuration passes its checks.
Enter authentication material only in the approved setup fields. Do not include it in documentation, screenshots for Support, or messages. Existing unchanged secrets may not display live verification codes.
Do not reset or duplicate an authenticator enrollment without approval from the account owner and security team. Resetting MFA can interrupt both human access and automated operations.
Multiple integrations to one provider
Decide with your security team whether integrations may share an account. Separate accounts improve ownership and rotation boundaries. If an existing integration already works, do not copy protected MFA material into another integration.
Troubleshoot safely
- Record the provider, integration friendly name, time, and displayed error.
- Use Copy diagnostics only after reviewing the output for sensitive organizational data.
- Share error text, not authentication material.
- Revalidate after the provider administrator corrects account policy or scope.
See Status and lifecycle for validation states.