IBM Support

IBM Verify User Guide

Product Documentation


Abstract

IBM® Verify adds an extra layer of protection to help prevent unauthorized access to your accounts. It provides a second verification step when authentication is required, such as approving a push notification or entering a one-time password (OTP).

Content

This user guide provides the following information for the IBM Verify mobile application:

IBM Verify adds an extra layer of protection to help prevent unauthorized access to your accounts. It provides a second verification step when authentication is required, such as approving a push notification or entering a one-time password (OTP).


Overview

IBM Verify is a mobile authentication app that provides the second factor when a connected service requires additional verification. With IBM Verify, you can:

  • Approve authentication requests from your mobile device.
  • Generate one-time passwords for accounts that support a standard authenticator app.
  • Manage multiple authentication accounts from a single app.
  • Receive alerts when someone attempts to access your account.
  • Use device biometrics, such as Face ID, Touch ID, or fingerprint authentication, when supported by your account and device.

Two-step verification

Two-step verification adds a second step to the authentication process to confirm that you are the person trying to access an account. The second step uses your mobile device in addition to your username and password.

Two-step verification process using IBM Verify

IBM Verify supports two authentication methods:

  • IBM Verify app - multi-factor authentication (MFA)
    IBM Verify sends a push notification to your mobile device when authentication is required. You review and approve or deny the request directly in the app. This method does not require you to type a code.
  • Authenticator app (OTP) - one-time password (OTP)
    IBM Verify generates a temporary one-time password on your mobile device. You enter the code on the verification screen to complete authentication. Use this method for services that support any standard authenticator app.

Two-step verification helps protect your account if your password is compromised because an additional verification step is always required. For more information about configuring authentication factors, see Configuring authentication factors.

Important: The authentication methods available to you depend on the configuration of your organization or online service.


Supported devices

IBM Verify supports the following mobile operating system versions:

  • iOS 18.6 or later
  • Android 10.0 or later

Install IBM Verify

Install IBM Verify on your mobile device before connecting an account.

  1. On your mobile device, open the App Store on iOS or the Google Play Store on Android.
  2. Search for IBM Verify.
    IBM Verify in the App Store          IBM Verify in the Google Play Store
                                       iOS                                                                            Android
  3. Tap Get on iOS or Install on Android.

Add an authentication method

Add an authentication method from the security settings of the account that you want to protect. This step generates the QR code that you use to connect the account to the mobile app.

Complete this procedure for each account that you want to protect.
Note: The exact navigation depends on your organization or online service. The following steps use the IBM Verify portal as an example.

  1. Sign in to the account you want to protect on a computer.
  2. Open the account or profile settings.
  3. Navigate to the security or authentication settings.
  4. Select the option to add a new authentication method.

    Add new method screen showing IBM Verify app and Authenticator app options
  5. Choose the authentication method that you want to add.
     

Authenticator app (OTP)

  1. Select Authenticator app and click Setup.
  2. Enter a name for the authenticator app.
  3. Click Next: Download the app.
  4. Click Next: Connect your authenticator.
    A QR code is displayed in the browser. Keep this screen open.
  5. Open IBM Verify on your mobile device.
  6. Tap the Scan QR code icon.

    IBM Verify home screen showing the Add an account option          IBM Verify home screen showing the Add an account option
                                       iOS                                                                      Android 

    If prompted, allow IBM Verify to access the camera.

    Camera permission prompt on iOS          Camera permission prompt on Android
                                       iOS                                                                  Android 
  7. Scan the QR code displayed in the browser.

    IBM Verify camera view for scanning a QR code          QR code scanner on Android
                                       iOS                                                                      Android 
  8. Review the account details and tap Yes, connect.

    Account details confirmation screen on iOS          Account details confirmation on Android
                                       iOS                                                                            Android 
  9. Tap Done. The OTP account appears in the Accounts list.

    Accounts list on iOS after OTP connection          Accounts list on Android after OTP connection
                                       iOS                                                                  Android 
     

IBM Verify app (MFA)

  1. Select IBM Verify app and click Add device.
  2. Click Next: Connect your account.
    A QR code is displayed in the browser. Keep this screen open.
  3. Open IBM Verify on your mobile device.
  4. Tap the Scan QR code icon. If prompted, allow IBM Verify to access the camera.
  5. Scan the QR code displayed in the browser.
  6. Review the account details and tap Yes, connect.
  7. (Optional) If prompted, tap Allow notifications to receive authentication requests.
    If you are not prompted, you can enable notifications manually. On your device, go to Settings > Notifications > IBM Verify and turn on Allow Notifications.

    Allow notifications prompt on iOS          Enable push notifications on Android
                                       iOS                                                                              Android 
  8. (Optional) If biometrics is available for your account, you can enable Face ID, Touch ID, or fingerprint authentication to quickly verify authentication requests. For more information, see Enable or disable biometrics.

    Biometrics setup on iOS          Biometrics setup on Android
                                       iOS                                                                              Android 
  9. Tap Done. The MFA account appears in the Accounts list.
    Note: In some configurations, the server automatically adds a TOTP account during registration. If a blue notification bar appears on the Success screen, a TOTP account has been added alongside the MFA account.

    Registration success on iOS          Registration success on Android
                                       iOS                                                                  Android 

Test your authenticator

To verify the connection, return to the browser and complete the following steps:

  1. Click Next: Test your authenticator.
  2. Open the newly added account in the IBM Verify mobile app.
  3. Enter the passcode displayed in IBM Verify into the Access code field in the browser.
  4. Click Next: Verify to confirm the account was added correctly.
    A success message is displayed.
  5. Click Done.

Authenticate with IBM Verify

After you connect an account, IBM Verify provides the second factor whenever a connected service requires additional verification - such as signing in, approving a transaction, or confirming a sensitive action. The steps depend on whether your account uses IBM Verify authentication or a one-time password.
Note: Connect the account to IBM Verify before you can use it for authentication.

Approve an authentication request

Use this method when the service asks you to verify the request with IBM Verify.

  1. Open the website or application that requires authentication.
  2. Enter your username and password and select Continue.
  3. Select IBM Verify if you are asked to choose an authentication method.
    • When IBM Verify sends a push notification to your mobile device, tap the notification to open the authentication request.
      If you do not receive a notification, open IBM Verify and tap the pending request in the Accounts tab.

      Accounts tab on iOS          Accounts tab on Android
                                         iOS                                                                  Android 
    • If the service displays a QR code instead of sending a push notification, open IBM Verify, tap Scan QR code, and scan the code displayed on the sign-in page.
  4. Review the request details carefully - including the service name, time, and any transaction information that is shown - and then tap Approve to confirm.

    Transaction approval screen on iOS          Transaction approval screen on Android
                                       iOS                                                                  Android 
  5. (Optional) If prompted, approve the sign-in request by using your device biometrics.
    Important: Only approve requests that you initiated. If you receive a request you did not expect, tap Deny and select This request is suspicious to report it. This alerts your organization that an unauthorized sign-in attempt may have occurred.

For more information, see Configuring authentication factors.

Verify with one-time password

Use this method when the service asks you to enter a code from an authenticator app.

  1. Open the website or application that requires authentication.
  2. Enter your username and password.
  3. Select Authenticator app or the equivalent OTP option.
  4. Open the IBM Verify app and select the account that you are authenticating with.
    Note: After you open the app, you are prompted to complete a biometric challenge before the passcode is displayed. This prompt appears only once.

    OTP account details on iOS          OTP account details on Android
                                       iOS                                                                  Android 
  5. Enter the passcode displayed in IBM Verify into the code field on the screen.
  6. Continue the authentication process.

Note: Time-based passcodes (TOTP) refresh automatically at regular intervals. By default, passcodes refresh every 30 seconds unless a different refresh period was configured when the account was created. If a passcode expires before you enter it, use the new passcode displayed in IBM Verify.


Manage accounts

Use the Accounts tab in IBM Verify to view and manage connected accounts.
Note: Changes that are made in IBM Verify affect only the mobile app. Removing an account from IBM Verify does not remove the authentication method from the online service.

Change an account name

  1. Open IBM Verify and tap Accounts.
  2. Select the account.
  3. Tap Edit.

    Edit account name on iOS          Edit account name on Android
                                       iOS                                                                        Android 
  4. Update Account name or Display username.
  5. Tap Save details.
     

Back up OTP accounts (iOS)

You can back up OTP accounts to iCloud so they can be restored when IBM Verify is reinstalled on a new or reset device.
Important: MFA accounts cannot be backed up using this feature. OTP backup is available on iOS only.

  1. Open IBM Verify.
  2. Go to Menu > Settings.
  3. Enable OTP backup.

    OTP backup setting on iOS
                                 iOS 
     

Reorder accounts

  1. Open IBM Verify and tap Accounts.
  2. Touch and hold an account, then drag it to the desired position.
    Reordering accounts on iOS          Reordering accounts on Android
                                       iOS                                                                    Android 

Remove an account

Important: Before removing an account from IBM Verify, make sure that you have another way to access the online service. Removing your only authentication method can prevent you from signing in.

Remove the authentication method from the online service first, then remove the account from IBM Verify.

  1. Sign in to the online service and open the account or security settings.
  2. Locate the authentication or sign-in methods.
  3. Remove IBM Verify or the authenticator account.
  4. Open IBM Verify and tap Accounts.
  5. Select the account.
  6. Scroll to the bottom and tap Remove account.

    Remove account on iOS          Remove account on Android
                                       iOS                                                                  Android 
  7. Tap Remove to confirm.
     

Enable or disable biometrics

Biometric authentication uses a supported device feature - such as Face ID, Touch ID, or fingerprint authentication - to verify you when IBM Verify requires additional device confirmation.

  • For iOS devices:
    1. Open Settings.
    2. Go to Apps > IBM Verify.
    3. Turn Face ID / Touch ID on or off.
  • For Android devices:
    1. Open IBM Verify.
    2. Go to Menu > Settings.
    3. Turn Biometric authentication on or off.

Troubleshooting

Use the following guidance for common problems when setting up or using IBM Verify.

I cannot find the QR code

Make sure that you have added an authentication method from the security settings of the account you want to protect. The QR code is displayed during that setup process.
For more information, see Add an authentication method.

I cannot scan the QR code

  • Make sure that IBM Verify has permission to use your device camera. On your device, go to Settings > Privacy > Camera and enable access for IBM Verify.
  • Make sure that you are scanning a QR code that is generated during the IBM Verify or authenticator app setup process. IBM Verify cannot process generic QR codes or URLs.
  • Make sure that the QR code is displayed clearly on the screen and is not obscured, blurry, or too small. Increase the browser zoom level if needed.
  • If you cannot scan the code at all, use the manual setup option instead. Return to the setup screen in your browser and look for an option to enter a setup key or code manually. For more information, see your service provider's documentation.
     

I did not receive an authentication notification

  • Make sure that notifications are enabled for IBM Verify. On your device, go to Settings > Notifications > IBM Verify and turn on Allow Notifications.
  • Make sure that your mobile device has an active internet connection.
  • On Android, disable battery optimization for IBM Verify. Battery optimization can prevent the app from receiving push notifications promptly. On your device, go to Settings > Apps > IBM Verify > Battery and select Unrestricted.
  • Open IBM Verify and check the Accounts tab for a pending request.
  • If no request appears, restart the authentication process.
     

My OTP code does not work

  • Make sure that you selected the correct account in IBM Verify.
  • Enter the current passcode displayed in IBM Verify. Time-based passcodes usually expire every 30 seconds.
  • Make sure the date and time on your mobile device are set to automatic.
  • IBM Verify only supports OTPs with 6 or 8 digits. If your account generates a code of a different length, contact your service provider.
     

I cannot approve an authentication request

Open IBM Verify directly and check the Accounts tab for a pending request. If no request appears, restart the authentication process.
If the problem continues, verify that the correct account is connected and that the device has an active internet connection.
 

I lost or replaced my phone

Take the following steps as soon as possible.

If you still have access to your account:

  1. Sign in to the affected account on a computer.
  2. Navigate to the security or authentication settings.
  3. Remove or unregister the lost device from the authentication methods.
  4. On your new or reset device, reinstall IBM Verify and re-enroll following the Add an authentication method procedure.
    Important: MFA accounts cannot be restored from backup. They must be re-enrolled manually after removing the lost device from the account's authentication methods.
     

If you cannot access your account:
Contact your account administrator or service provider immediately. They can revoke access for the lost device and help you regain entry to your account.
Note: For account-specific recovery, contact the administrator or service provider that manages your account. IBM Verify cannot recover access to customer accounts.


Frequently asked questions

What is the difference between IBM Verify authentication and OTP?

IBM Verify authentication sends a push notification to your mobile device. You approve or deny the request directly in the app without entering a code. OTP authentication generates a temporary passcode in IBM Verify that you enter manually on the verification screen. Your organization or service determines which method is available.
 

Can I use IBM Verify for multiple accounts?

Yes. IBM Verify can manage multiple connected accounts. Each account must be set up and connected separately.
 

Can I use IBM Verify on more than one device?

Yes. You can install IBM Verify on multiple devices. Each device must be registered separately with the account or service you want to protect.
 

Can I open the QR code scanner without navigating through the app?

You can launch the QR code scanner directly from the app icon's context menu, without opening IBM Verify first. Touch and hold the IBM Verify app icon on your home screen, then select Scan QR code from the menu that appears.

QR code scanner shortcut on Android
                 Android

You can also skip the QR code introduction screen so that subsequent scans open the scanner immediately. Inside the app, navigate to the QR code scanner and enable the option to skip the introduction screen on future visits. On Android, this option is available from version 3.1.3.
Camera permission prompt on iOS          Camera permission prompt on Android
                                   iOS                                                                  Android 
 

Can I back up my accounts?

OTP accounts can be backed up to iCloud on iOS and restored when IBM Verify is reinstalled. MFA accounts cannot be backed up using this feature.
 

Why does IBM Verify ask for biometric authentication?

Your organization or service may require device biometrics as an additional verification step. IBM Verify supports Face ID, Touch ID, and fingerprint authentication where available on the device.

Your biometric data never leaves the device. Authentication is handled entirely by your device's operating system. Your fingerprint, face, or other biometric data is never sent to, stored by, or accessible to IBM Verify or your organization. Your device's secure hardware performs the biometric match locally and returns the result to the app.
 

What should I do if I delete IBM Verify?

Reinstall IBM Verify and reconnect your accounts. If you previously enabled OTP backup on iOS, you can restore your OTP accounts from iCloud.
 

What should I do if my account is locked or I cannot sign in?

Contact the administrator or service provider that manages your account. IBM Verify cannot change account credentials or recover access to accounts managed by another service.
 

Can I use IBM Verify without an internet connection?

OTP (one-time password) accounts work fully offline - IBM Verify generates passcodes locally on your device without needing a network connection. MFA (push approval) accounts require an active internet connection on both your device and the service initiating the request. If your device is offline and you need to authenticate with an MFA account, connect to a network and try again, or contact your service provider about alternative access options.
 

What should I do if I receive an authentication request I did not initiate?

Tap Deny and select This request is suspicious to report the request. This alerts your organization that an unauthorized sign-in attempt may have occurred. Do not approve requests you did not initiate, even if the request appears to come from a service you use.
 

What is the difference between an MFA account and a TOTP account in the Accounts list?

An MFA account appears when you enrolled using the IBM Verify app method. It receives push notifications and shows pending approval requests. A TOTP account appears when you enrolled using the Authenticator app method, or when one was added automatically alongside an MFA account during registration. TOTP accounts display a rotating numeric passcode that you enter manually. Both types can coexist in the Accounts list.
 

Additional help
Contact IBM Support: https://www.ibm.com/support

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSRGTL","label":"IBM Security Verify Access"},"ARM Category":[{"code":"a8m0z000000cxuHAAQ","label":"Security Verify Access"},{"code":"a8m0z000000cxuMAAQ","label":"Security Verify Access-\u003EAdvanced Access Control"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.0.0;and future releases"}]

Document Information

Modified date:
18 September 2026

UID

swg27048979