Multi Factor Authentication

Adaptive Multi Factor Authentication

Spriv pairs the workstation with the phone environment, then verifies both in the background. If they match, the login clears silently. If they don't, the user gets challenged.

Adaptive Multi Factor Authentication authorization prompt on the Spriv mobile app
Adaptive MFA · Background verification · No user interaction
0 ms
Typical time to clear the second factor
0
Taps required from the user
0+
Countries covered by SMS methods
0 h
Pairing link expiration window
Watch it work

What is Spriv's Adaptive Multi Factor Authentication?

Five methods, one console

Pick a tab to see how each method behaves

Adaptive Two Factor Authentication

Spriv's patented Adaptive Two Factor Authentication compares the phone's location fingerprint with the workstation's device fingerprint. When Spriv's risk-based engine finds a match, the transaction is approved automatically no code, no tap. When the fingerprints don't line up, the user is prompted to manually allow or deny the request.

  • Pairing links the user's phone to their email once, via a unique URL valid for 48 hours.
  • After the user installs the Spriv app and opens the pairing link on the phone, pairing completes.
  • Spriv notifies your site the moment pairing succeeds.
  • Your integration supplies browser agent data such as cookies to Spriv's API to power the fingerprint comparison.
Best for

Every user, on every workstation. This is the entry point to Adaptive MFA every other method builds on it.

Fingerprint match, automatic approval. A mismatch simply falls back to a manual Allow/Deny prompt.
Adaptive Multi Factor Authentication authorization prompt on the Spriv mobile app
Authorization screen · Spriv app

Allow / Deny for high-risk moments

An optional secondary factor for transactions that deserve an explicit human confirmation. Send the transaction info to Spriv over the API, receive back the user's allow-or-deny decision.

  • Address change on the account
  • Wire transfer above a threshold
  • RDP or SSH login to a production server
  • Password reset on a privileged account
  • Any custom event you flag as "high risk"
Best for

Exception events not every login. Reserve Allow/Deny for the transactions that a user should consciously confirm.

Watch out for repetition poisoning. If you prompt Allow/Deny on every routine action, users learn to approve without reading which undoes the security benefit. Keep it rare.
Allow / Deny push prompt on the Spriv mobile app
Allow / Deny prompt

SMS Code universal MFA

A seven-digit code sent to the registered handset. The user types the code once during account activation, then never sees it again unless you explicitly trigger it.

  • No app install works on any phone with SMS.
  • Familiar interaction every user already knows it.
  • Covers users on feature phones or shared devices.
  • Works even when Spriv's app isn't installed yet.
Best for

First-time activation, and as a fallback method for users who can't install an app.

Works in more than 200 countries. Spriv routes SMS through global carriers so the same code flow delivers everywhere.
One-way SMS MFA on the Spriv mobile app
SMS code · One-way

Two-way SMS closing the loop

Spriv sends an SMS asking for a reply. When the user replies, we push their answer to your endpoint via HTTP POST. It's a genuine second communication channel separate from the login channel.

Example prompt. "Did you buy a laptop from 'examplecompany' for $476? Reply yes and we ship it. Reply no and we cancel the order."
  • E-commerce order confirmation before shipping
  • Transaction verification on unusual purchases
  • Account changes requiring explicit customer confirmation
  • Fraud-flag replies routed straight to your backend
Best for

Interactive out-of-band confirmations where the user's actual reply text carries meaning not just a tap.

Two-way SMS verification on the Spriv mobile app
Two-way SMS · Reply-based

TOTP offline-safe

Standard RFC 4226 time-based one-time passwords. Six digits generated on the phone using its internal clock, refreshed every 30 seconds. Works even when the phone has no internet or cellular signal.

  • Users traveling to areas with poor reception
  • Air-gapped or restricted networks
  • Teams already carrying an authenticator app
  • Compliance frameworks that specifically require TOTP
Best for

Fallback in low-connectivity scenarios, or as a familiar auxiliary factor alongside Adaptive MFA.

Standards-compliant. RFC 4226 + 30-second TTL the same protocol every enterprise authenticator app already speaks.
TOTP one-time password on the Spriv mobile app
TOTP · 30-second code

Pairing the one-time setup

Pairing is the only setup step your user ever performs. Once it's done, every future login clears silently in the background no more approvals, no more codes.

  • Add the user's email in the Spriv admin console.
  • Spriv emails a unique pairing URL to the user.
  • User installs the Spriv app on their phone.
  • User opens the pairing URL on the phone pairing completes.
  • Spriv pushes a webhook back to your site the moment pairing succeeds.
  • URL expires in 48 hours reissue any time (new phone, expired link, etc.).
Best for

Every user, on every workstation. This is the entry point to Adaptive MFA no other method skips it.

One approval. Everything after that is automatic. The user do not need to authenticate during a normal login again.
Adaptive Multi Factor Authentication authorization prompt on the Spriv mobile app
Authorization screen · Spriv app
Explore

Related methods

Checkit!

Two free users, two free servers, no credit card

Install in under five minutes. See adaptive MFA authenticate a real login in the background.