← CoauthGuide

Salesforce Shared-Login MFA Workaround (2026)

By Kalpesh Mahida · Updated August 29, 2026

If you searched for a Salesforce shared-login MFA workaround, you probably had one that stopped working in 2026: a shared authenticator app or a shared verification code. Phishing-resistant MFA killed that. This guide covers the workarounds that still clear the bar, the ones that do not, and how to share a login the encrypted way.

Why the old workaround stopped working

The classic trick was to enroll a shared account in an authenticator app and pass the six-digit code around, or share the TOTP seed. For privileged Salesforce users in 2026, a one-time code no longer clears MFA. The whole point of phishing-resistant MFA is that the factor is bound to a device and cannot be typed in from a code someone messaged you.

Workarounds that still work

Temporary Verification Code

An admin can mint a Temporary Verification Code for a user, valid 1 to 24 hours. It works for occasional access. It is tedious for a team that needs the login often, and a typed code is weaker than the passkey it replaces.

A shared password manager holding the passkey

Store a software passkey for the account in a manager that can share it. Salesforce guidance for shared accounts points to exactly this. Good if you already run a manager across the team.

A single-purpose shared-login tool

Coauth shares one login, passkey or password, for free, sealed to each teammate, with a clean revoke. It fits when you only need to share one account and do not want to roll out a suite.

What is not a workaround

  • Turning off MFA for the account. For privileged users this is not a real option and defeats the security you are required to have.
  • Sharing a TOTP seed or codes. It no longer clears the bar for privileged users and was always the weakest link.
  • Pasting the password in chat. That is not a workaround, it is the risk the mandate is trying to remove.

The encrypted-share workaround, step by step

  1. Install Coauth and secure your vault with your device passkey.
  2. Register a new software passkey for the account through Coauth, or save the login.
  3. Create a team and share it in.
  4. Invite the people who need access. They sign in from their own browser.
  5. Remove anyone who leaves. The key rotates.

The honest caveat

Any shared login trades individual accountability for convenience. Use these workarounds for genuine service accounts, and keep named people on their own accounts with their own passkeys.

Frequently asked questions

Can I still share a Salesforce authenticator code?

Not for privileged users. A one-time code no longer clears phishing-resistant MFA. Use a shared passkey in a manager or a tool like Coauth instead.

Is there a way to share the login that Salesforce allows?

Yes. Salesforce guidance for shared accounts points to storing the credential in a password manager that supplies the verification method. That is a sanctioned pattern for a genuine service account.

Can I just disable MFA for a shared account?

For privileged users that is not a viable or safe path. The better answer is to share the phishing-resistant factor through an encrypted vault.

What is the fastest workaround for regular team access?

A shared vault or a free tool like Coauth, so each member signs in with the shared passkey from their own device without minting a new code every time.

Share one login without buying five seats

Coauth is live on the Chrome Web Store and free to start. Zero-knowledge, one-click sign-in, revoke anyone in a click.

Add Coauth to Chrome
See it work

How Coauth shares a login.