Three Authentication Methods
Email OTP — A 6-digit one-time code is sent to the admin’s email address on every login.
Phone / SMS OTP — A 6-digit code is sent via SMS (Twilio or Vonage/Nexmo).
Google Authenticator (TOTP) — Time-based codes using any TOTP app (Google Authenticator, Authy, 1Password, etc.). No email or SMS dependency.

