What two-factor authentication does on kota
Two-factor authentication adds a second verification step to your kota login. After you enter your username and password, our system asks for a code from your phone. This code is either sent via SMS or generated by an authenticator app you install. Only after you enter the correct code can you access your account.
The same 2FA requirement applies when you request a withdrawal. After you submit a withdrawal request, we send a verification code to your phone. You enter this code to confirm the withdrawal. This prevents someone who knows your password from withdrawing your funds without your knowledge.
2FA does not affect your gameplay. Once you log in successfully, you can play slots, join live-dealer tables, or place sportsbook bets without entering additional codes. The authentication only happens at login and withdrawal—not during each game or bet.
Setting up 2FA on your kota account
To enable two-factor authentication on kota, log into your account and navigate to Account Settings. Look for the Security section and select "Enable Two-Factor Authentication". Our system offers two options:
- SMS-based 2FA. We send a six-digit code to your registered phone number via SMS. You enter this code on the login screen. SMS codes expire after a few minutes, so you must enter them quickly.
- Authenticator app 2FA. You download an authenticator app (such as Google Authenticator, Microsoft Authenticator, or Authy) on your phone. During setup, we provide a QR code that you scan with the app. The app then generates a new six-digit code every 30 seconds. You enter the current code at login.
We recommend authenticator apps over SMS because they are not vulnerable to SIM-swap attacks (where someone tricks your phone provider into transferring your number to a different phone). However, SMS is simpler if you do not want to install an app.
Save your backup codes during 2FA setup
When you enable 2FA on kota, we provide backup codes. Store these codes in a safe place (not on your phone). If you lose access to your phone, you can use a backup code to log in and disable 2FA.
After you choose your 2FA method and confirm setup, 2FA is active immediately. Your next login will require the verification code.
Using 2FA during login and withdrawal
Once 2FA is enabled, here is what happens each time you log into kota:
- Enter your username and password on the login page.
- Click "Sign In". Our system verifies your credentials.
- If correct, we ask for your 2FA code. If you chose SMS, we send a code to your phone. If you chose an authenticator app, open the app and read the current code.
- Enter the code on the screen. If correct, you are logged in. If incorrect or expired, try again.
The same flow applies to withdrawals. After you submit a withdrawal request and confirm the amount and payment method, we send a 2FA code to your phone. You enter this code to authorise the withdrawal. This prevents accidental or fraudulent withdrawals.
2FA during peak gaming hours
2FA does not slow down your gameplay. Once you log in, you can spin Mahjong Ways, Gates of Olympus, Aviator, or any other slot on kota without re-entering codes. The authentication only happens at the start of your session.
During busy periods—such as around Idul Fitri, Idul Adha, or when major Liga 1 matches are live—SMS delivery may be slightly delayed. We recommend using an authenticator app for faster, more reliable codes during peak times.
Disabling or changing your 2FA method
If you want to disable 2FA or switch from SMS to an authenticator app (or vice versa), log into your kota account and go to Account Settings. Select the Security section and choose "Manage Two-Factor Authentication". You can disable 2FA entirely or change your method.
If you disable 2FA, your account becomes less secure. We do not recommend this unless you have a specific reason. If you change your 2FA method, the old method stops working immediately and the new method takes effect.
Account recovery if you lose your 2FA device
If your phone is lost, stolen, or damaged, and you cannot access your 2FA codes, you can still recover your kota account. Here is the process:
- On the login page, click "Trouble logging in?" or "Forgot password?".
- Enter your username or email address.
- Our system sends a recovery link to your registered email address.
- Click the link and follow the prompts to verify your identity (we may ask for a photo of your ID or other verification).
- Once verified, you can reset your password and disable 2FA temporarily.
- After regaining access, set up 2FA again with your new phone or device.
Account recovery typically takes one business day if you respond promptly to our verification requests. Our support team operates during standard business hours. If you need urgent assistance, contact us via the support form on our website and explain your situation.
2FA benefits
- Protects against password theft
- Prevents unauthorised withdrawals
- Works across all kota games and features
2FA considerations
- Requires access to your phone at each login
- SMS codes can be delayed during peak times
- Loss of phone requires account recovery process
2FA and payment methods on kota
Two-factor authentication works with all our payment methods: DANA, e-wallet, mobile banking, local payment, online payment, e-wallet, and bank transfers via mobile banking, local payment, online payment, and e-wallet. When you deposit or withdraw using any of these methods, 2FA protects your account during the transaction.
If you use 2FA and request a withdrawal to mobile banking or local payment, for example, we send a 2FA code to your phone. You enter this code to confirm the withdrawal. Your payment provider then processes the transfer according to their own schedule. 2FA does not affect payment processing times—it only adds a security verification step on our side.
Users in Jakarta, Surabaya, Bandung, Medan, and Semarang all use the same 2FA system. There are no regional differences in how 2FA works on kota.
