Skip to Help content

Tell login methods apart

Choose between email codes, 2FA, and passkeys

Outcome: Understand which sign-in prompt you are seeing and which credential belongs there.

Identify the prompt

  • Email code: a six-digit code sent from noreply@ezformz.net. This is the normal production sign-in method and expires after 15 minutes.
  • 2FA code: a changing six-digit code from a TOTP authenticator app. You see this only after the email code when 2FA is enabled.
  • Recovery code: one of the one-time codes saved when 2FA was enabled. Use it instead of an authenticator code.
  • Passkey: a credential approved by your device, password manager, or hardware key. It can sign you in without waiting for an email code.

Normal production sign-in does not use an account password. A password prompt belongs to a password-protected buyer form or a development-only sign-in path, not the standard production account login.

Complete the right flow

  1. For ordinary sign-in, enter your email and then the newest email code.
  2. If a second-factor screen appears, enter the current authenticator code or choose the recovery-code option.
  3. To use a passkey, choose Sign in with passkey and approve the browser prompt.

If an authenticator code fails, set the device time automatically, wait for the next code, and try again on the same screen. Request a new email code only if the sign-in expires or too many second-factor attempts were rejected.

A passkey is an alternative sign-in method, not an extra prompt after the email code. The browser binds it to the EZFormz site, which makes it resistant to a look-alike site's request. Still inspect the browser address and approve passkey prompts only when you intended to sign in to ezformz.net.

An authenticator app and its recovery codes are one factor set. A recovery code is consumed when used. A passkey may be device-bound or may sync through its password manager; EZFormz cannot restore a passkey that was removed from that device or manager.

If access is lost

Try another registered passkey, then an unused recovery code. If neither is available, follow Set up 2FA, passkeys, and recovery. Email-only 2FA reset is intentionally unavailable.

Removing a passkey or disabling 2FA does not sign out sessions that already exist. Account email change is the current self-service action that revokes other sessions while keeping the session performing the change.