# Two-Factor Continuity Instructions AI Agent Connect

> Two-Factor Continuity Instructions MCP provides a structured framework for managing multi-factor authentication (MFA) continuity. Your AI client uses this MCP to identify necessary recovery assets and verify governance rules, allowing it to provide safe, step-by-step instructions to authorized recipients without ever exposing sensitive credentials.

## Overview
- **Category:** security
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_md66suiqX7Av24o4UvtpbJNmLzHGfz2hAQdD9d01/ai-agent-connect
- **Tags:** mfa, recovery, continuity, security, authentication

## Description

When an account holder loses access to their MFA device, the recovery process often becomes a security bottleneck. This MCP bridges that gap by giving your AI client the logic needed to manage continuity events safely. Instead of handing over raw passwords or secret keys, your agent uses this MCP to determine if a recovery attempt is legitimate based on role-based access controls and specific governance triggers. 

You can use it to walk an authorized person through the exact steps needed to regain access, such as locating a physical hardware module or an encrypted drive. The MCP handles the heavy lifting of checking eligibility and verifying that all necessary conditions are met before any instructions are issued. It keeps the sensitive data tucked away, only surfacing the procedural guidance required to resolve the lockout. It is built for environments where MFA recovery must be both fast and strictly governed.

## Tools

### get_recovery_protocol
Generates a safe, step-by-step instructional guide for a specific recipient to regain access to an account.

### locate_recovery_assets
Identifies which physical devices or storage locations need to be accessed for a recovery attempt.

### validate_recipient_eligibility
Confirms if a specific person or role is permitted to participate in the recovery of a specific account.

### verify_release_conditions
Checks if the necessary governance requirements are met to trigger an MFA recovery.

## Prompt Examples

**Prompt:** 
```
I am a Department Lead. What are the recovery steps for a Corporate account?
```

**Response:** 
```
To recover access to the Corporate account, first locate the encrypted USB drive in the department safe. Once retrieved, follow the standard verification protocol with your supervisor.
```

**Prompt:** 
```
Where can I find the recovery assets for an Administrative account?
```

**Response:** 
```
Administrative assets are stored in the high-security dual-lock vault. You will need to coordinate with the security team to access the hardware security module.
```

**Prompt:** 
```
Check if the recovery for a Personal account is authorized with the trigger 'primary_user_incapacitated'.
```

**Response:** 
```
Yes, the release conditions for Personal accounts are met with the provided trigger.
```

## Capabilities

### Protocol Generation
Your agent creates custom instructional guides for users needing account access.

### Asset Identification
The AI identifies the specific physical or digital locations where recovery materials are kept.

### Eligibility Verification
Your client checks if a user's role allows them to initiate a recovery.

### Governance Enforcement
The MCP verifies that all required conditions are met before releasing recovery instructions.

## Use Cases

### Emergency Account Recovery
An employee loses their MFA device and needs to know the specific steps to regain access via a hardware module.

### Role-Based Access Validation
A manager needs to confirm if a specific team member is authorized to trigger a recovery for a corporate account.

### Governance Triggering
The system checks if specific conditions, like a user being incapacitated, allow for a recovery process to begin.

### Physical Asset Locating
An authorized user asks where the encrypted recovery drives are stored to complete an access request.

## Benefits

- Prevents credential exposure by providing procedural instructions instead of raw secrets.
- Enforces role-based access control during emergency recovery events.
- Automates the verification of governance requirements for MFA triggers.
- Provides clear, actionable guidance for authorized personnel.

## How It Works

Connect the MCP to your AI client to start managing MFA continuity through structured tools.

1. Connect your preferred MCP-compatible client to the Vinkius hosted MCP.
2. Your agent identifies the user's role and the account type needing recovery.
3. The agent uses the MCP to validate eligibility and check governance conditions.
4. The MCP identifies the necessary physical or digital recovery assets.
5. Your agent delivers the step-by-step recovery instructions to the authorized user.

## Frequently Asked Questions

**Does this MCP expose sensitive MFA credentials?**
No. The MCP is designed to provide natural language instructions on where to find recovery materials without ever exposing the actual credentials.

**How does the MCP ensure only authorized people get recovery steps?**
It uses the validate_recipient_eligibility tool to confirm if a person or role is permitted to participate in the recovery process.

**Can I use this with Claude or Cursor?**
Yes. You can connect this MCP to any MCP-compatible client, including Claude, Cursor, and Windsurf.

**What happens if the governance conditions are not met?**
The verify_release_conditions tool will check the requirements, and the agent will not be able to proceed with the recovery instructions if the conditions are not satisfied.

**Where is the MCP hosted?**
Vinkius hosts and manages the MCP, so it is ready to use immediately after you connect your client.

**Does this server expose actual passwords or backup codes?**
No. The server is strictly designed to provide instructions on where to find assets and how to proceed. It never returns actual passwords, secret keys, or backup codes.

**How does the server determine if a user can start a recovery?**
The server uses `verify_release_conditions` to check if the required governance triggers, such as dual-authorization, have been met for the specific account category.

**Can any user access Administrative accounts?**
No. Access is strictly governed by roles. You can use `validate_recipient_eligibility` to confirm if a role, such as a System Administrator, is permitted to access a specific tier.
