Reference

Two Factor Setup on koko123

Adding two factor authentication to your koko123 account takes a few minutes and keeps your wallet connections — including DANA, OVO, and GoPay — protected from unauthorised access. Players in Depok and across Indonesia can complete the setup entirely from their mobile device.

Authenticator AppSMS VerificationAccount Lock ProtectionWallet Access Control
koko123 Two Factor Setup on koko123
SECURITY STANDARDS

How We Protect Your Two Factor Process

Two factor authentication on koko123 is built around the same account security practices that protect your wallet deposits and withdrawal requests. Here's what's in place behind the setup flow.

Time-Based Code Expiry

Every TOTP code generated by your authenticator app is valid for 30 seconds only. Expired codes are rejected outright, so intercepted codes can't be reused against your account.

Backup Code System

When you activate two factor setup, we generate a set of single-use backup codes. Store them offline — they're the recovery path if you lose access to your authentication device.

Device Session Tracking

koko123 tracks which devices have completed two factor verification. A new device always triggers the second step, regardless of whether the session cookie is present.

Wallet Link Protection

Your connected wallets — DANA, OVO, GoPay — can only be modified after two factor confirmation. Withdrawal route changes require a fresh authentication code every time.

koko123 What Two Factor Setup Covers on Your Account

What Two Factor Setup Covers on Your Account

Two factor authentication adds a second verification step each time you log in. After you enter your password, koko123 sends a one-time code — either via SMS to your registered number or through an authenticator app like Google Authenticator. You confirm the code and you're in. The setup lives inside Account Settings under the Security tab. We recommend the authenticator app route:

codes are generated offline, they expire in 30 seconds, and they aren't vulnerable to SIM swap attempts the way SMS codes can be. Once active, any login attempt from an unrecognised device triggers the second step automatically.

SETUP HELP PATHS

Get Help With Two Factor Setup

If you hit a snag during setup — a code that won't arrive, a lost authenticator device, or an account locked after too many failed attempts — our support team has specific recovery paths for each situation. Reach us through any of the channels below.

Live Chat Connect directly from the account page. Our team handles two factor recovery requests, including backup code redemption and authenticator resets, without you needing to email first.
Email Support Send your registered account email and a description of the issue to our support address. Two factor unlock requests are handled with identity verification to keep your account safe.
Account Recovery Flow If you've lost access to both your authenticator and backup codes, the in-app recovery form walks you through a step-by-step identity check tied to your registered payment wallet.

Two Factor Setup Glossary

Short definitions for the terms you'll run into when setting up and managing two factor authentication on your account.

01
What is TOTP?

Time-Based One-Time Password. A code generated by an authenticator app using the current time as input. Each code is valid for 30 seconds and cannot be reused after it expires.

02
What is a backup code?

A single-use recovery code generated when you first activate two factor setup. Used when you can't access your authenticator app — each code works once, then becomes void.

03
What is SIM swap risk?

A method where someone convinces a mobile carrier to transfer your number to their SIM. This lets them intercept SMS verification codes, which is why app-based TOTP is considered more secure.

04
What does 'trusted device' mean?

A device that has previously completed two factor verification on your account. Some platforms skip the second step on trusted devices; koko123 applies the second step every session by default.

05
What is account recovery verification?

An identity confirmation process used when you've lost access to your two factor method. Typically involves matching your registered email, phone, and linked payment wallet details.

06
What is an authenticator app?

A mobile application — such as Google Authenticator or Authy — that generates TOTP codes. The app works offline and is not dependent on your mobile carrier for code delivery.

Common Questions About Two Factor Setup

Everything you need to know before and after you activate two factor authentication on your koko123 account.

Go to Account Settings, open the Security tab, and select Two Factor Authentication. Scan the QR code with Google Authenticator or Authy, enter the first generated code to confirm, then save your backup codes somewhere offline.

Use one of your saved backup codes to log in. Once inside, go to Security Settings and reset your authenticator by scanning a new QR code on your replacement device. If you've lost the backup codes too, contact support for identity-verified account recovery.

Yes. During setup you can choose SMS delivery to your registered mobile number. Note that SMS codes depend on your carrier and can be delayed. The authenticator app option generates codes locally and doesn't rely on network delivery.

Yes, in a protective way. Any change to your linked wallet details — including DANA, OVO, and GoPay withdrawal accounts — requires a fresh two factor code. This prevents unauthorised route changes even if someone has your password.

koko123 generates a set of backup codes when you first activate two factor setup. Each code is single-use. If you've used most of them or suspect they've been exposed, regenerate the set from the Security tab — the old codes are invalidated immediately.

Every login session on koko123 requires the second step, not only new devices. This keeps your account secure even if someone accesses it from a previously used device without your knowledge.
Reference

Two Factor Setup

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.