Scan the QR code with Google Authenticator, then enter the 6-digit code
Informational prompt on login after mandatory 2FA setup returns a QR (auth.scanQrThenEnterCode). Not a failure — next step instructions.
Why this happens
POST /api/auth/mandatory-2fa/setup succeeded; the UI asks the member to scan and confirm with a 6-digit code. Distinct from empty-code Enter the 6-digit code from your authenticator app validation and from setup-failed errors.
Diagnose and fix
1. Open Google Authenticator (or compatible app); scan the QR.
2. Enter the current 6-digit code to confirm.
3. If the QR never loaded, see Could not load authenticator setup — try again / start-setup siblings.
4. Lost phone later: staff Reset user 2FA / sessions.