Reference
What it does
The mfa module brings multi-factor authentication into consensus: accounts can enroll additional factors, and designated sensitive operations — account recovery among them — require satisfying an on-chain MFA policy before they execute.
Because the policy check happens in the state machine rather than in a client app, MFA cannot be stripped by a malicious interface: a transaction that doesn't carry the required factors simply fails validation.
Why it exists: Key compromise is the dominant failure mode of blockchain accounts. For a chain that carries identity records and payment streams, single-signature security is not enough — MFA enforced by the protocol itself closes the gap between wallet security and account security.
State
Primary objects
| Concept | Definition |
|---|---|
Factor enrollment | Registering an additional authentication factor against an on-chain account. |
Step-up authentication | Requiring stronger factors for higher-risk operations like recovery. |
Messages
Messages & queries
Message and query surfaces are documented at implementation level in the module docs ↗ and the source ↗. The objects above are the state those messages create and transition.
Connections
Module interactions
Flows
Core flow
- Enroll — Register factors. Additional authentication factors are enrolled against the on-chain account.
- Govern — Policy names operations. Chain configuration designates which operations demand MFA — recovery, privileged roles, and their kin.
- Step up — Sensitive flows challenge. High-risk operations require satisfying the on-chain policy before they execute.
- Fail closed — Missing factors fail. Non-compliant transactions fail validation regardless of which client submitted them.
Questions
Asked about x/mfa
Why put MFA on-chain instead of in wallets?
Key compromise is the dominant account failure mode, and for a chain carrying identity records and payment streams, single-signature security is not enough. Protocol-enforced factors close the gap between wallet security and account security.
What is step-up authentication?
Requiring stronger factors for higher-risk operations like account recovery — the policy escalates with the stakes of the action.
How does MFA relate to VEID?
MFA layers on VEID identity for step-up verification on sensitive flows, and privileged role-holding accounts can be required to carry stronger authentication.
Related