As an alternative to TOTP for MFA, make the Second Life app on Android and Apple devices act as a MFA factor for logging in: Log in on Second Life app, in settings add the current device as a trusted factor for MFA When logging in on a new (different) device, and periodically, if enabled like stated above, send a notification to the trusted device asking if the user is trying to log in on another device, and have the user pick a number that corresponds to one showing on the other device's screen. Adobe, Microsoft and Google all three uses this for securing logins while making it easier to use than reading and typing a code in time before it changes.