# Web3auth v10 breaks MFA setup on v9

**URL:** <https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971>\
**Category:** Embedded Wallets (Web3Auth)\
**Tags:** web3auth\
**Created:** [March 13, 2026, 1:28pm UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971 "2026-03-13T13:28:23Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeanbenoit](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/jeanbenoit/32/2811_2.png) [@jeanbenoit](https://builder.metamask.io/u/jeanbenoit)\
**Post date:** [March 13, 2026, 1:28pm UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/1 "2026-03-13T13:28:23Z")

</div>

Hi,  
There is a problem of MFA when upgrading from web3auth v9 to web3auth v10.

In v9 we was using custom provider for social logins: discord, google, X and facebook.

We recently switched to web3auth v10 and now our users are blocked on MFA, the page is loading indefinitively.  
When checking in console, errors are:

- **Google:** invalid scope
- **Discord:** incorrect anwser

The problem seems to be this one:  
In v9 custom providers passed to web3auth was also used for MFA.  
So our users have validated their MFA with our own custom provider.

But now with v10 custom providers are not used anymore for MFA, so when our users are trying to connect to their wallet and validate MFA they got an error because provider use is web3auth provider.

We are using the last version of web3auth: **10.15.0**

Thank you.

---

<div class="post-metadata">

**Author:** ![holyyy](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/holyyy/32/1556_2.png) [@holyyy](https://builder.metamask.io/u/holyyy)\
**Post date:** [March 16, 2026, 3:27am UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/4 "2026-03-16T03:27:19Z")

</div>

Hi @jeanbenoit You can just ask your questions here and we will follow up.

Didi you check with the migration guide here?

> **[Migrating Custom Authentication from v9 to v10 | MetaMask developer...](https://docs.metamask.io/embedded-wallets/sdk/js/migration-guides/modal/v9-to-v10/custom-authentication/)**
>
> Comprehensive guide for migrating Web3Auth custom authentication configurations from verifiers to connections in v10.

Kindly let us know the details if your issue still exists.

---

<div class="post-metadata">

**Author:** ![jeanbenoit](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/jeanbenoit/32/2811_2.png) [@jeanbenoit](https://builder.metamask.io/u/jeanbenoit)\
**Post date:** [March 16, 2026, 7:10am UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/5 "2026-03-16T07:10:15Z")

</div>

Hi,  
The problem is only when users has a MFA setup that protected their account.  
Users without MFA are able to connect to their accounts and the right AA address.

---

<div class="post-metadata">

**Author:** ![holyyy](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/holyyy/32/1556_2.png) [@holyyy](https://builder.metamask.io/u/holyyy)\
**Post date:** [March 16, 2026, 9:12am UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/6 "2026-03-16T09:12:44Z")

</div>

May I know if you have configured the social logins on the Web3Auth Dashboard?

1. Log into your Web3Auth Dashboard and select your project.

2. Navigate to the **Authentication** tab.

3. Under **Social Logins** , click the **gear icons** to create custom connections for Discord, Google, etc.

4. Input the Connection ID and the Client ID.

---

<div class="post-metadata">

**Author:** ![jeanbenoit](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/jeanbenoit/32/2811_2.png) [@jeanbenoit](https://builder.metamask.io/u/jeanbenoit)\
**Post date:** [March 16, 2026, 3:03pm UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/7 "2026-03-16T15:03:36Z")

</div>

Yes as stated in my message, users without MF are able to connect to their account and they are connected to the right address.

---

<div class="post-metadata">

**Author:** ![holyyy](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/holyyy/32/1556_2.png) [@holyyy](https://builder.metamask.io/u/holyyy)\
**Post date:** [March 17, 2026, 1:57am UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/8 "2026-03-17T01:57:49Z")

</div>

Understood. I have passed your case to our team, and we will reply you as soon as we can.

---

<div class="post-metadata">

**Author:** ![yashovardhan](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/yashovardhan/32/1526_2.png) [@yashovardhan](https://builder.metamask.io/u/yashovardhan)\
**Post date:** [March 17, 2026, 5:18pm UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/9 "2026-03-17T17:18:56Z")

</div>

Hey @jeanbenoit

As I looked into our previous SDKs as well, the custom authentication you use for logging in, is not used by our MFA system. This is because the second login is triggered by our own domain `auth.web3auth.io` and we cannot get access to the token that you are getting in your domain directly.

Hence this particularly is not the issue over here. The issue is related to something else which we will be able to determine after seeing the exact console logs. Is it possible for you to share the exact console information when this error is happening? Additionally any screen recording/ live demo of the app will also help us test further.

---

<div class="post-metadata">

**Author:** ![jeanbenoit](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/jeanbenoit/32/2811_2.png) [@jeanbenoit](https://builder.metamask.io/u/jeanbenoit)\
**Post date:** [March 18, 2026, 2:40pm UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/10 "2026-03-18T14:40:52Z")

</div>

Hi @yashovardhan,  
How can I send you the 2 videos of v9 and v10 ?  
There is personal informations i would like not to share on public forum.

Thanks you.

---

<div class="post-metadata">

**Author:** ![holyyy](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/holyyy/32/1556_2.png) [@holyyy](https://builder.metamask.io/u/holyyy)\
**Post date:** [March 24, 2026, 2:14am UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/11 "2026-03-24T02:14:49Z")

</div>

Hi @jeanbenoit ! So sorry for the late reply. If you have concerns about sending videos here, you can DM to @yashovardhan on telegram: [t.me/yashweb3](http://t.me/yashweb3)

---

<div class="post-metadata">

**Author:** ![jeanbenoit](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/jeanbenoit/32/2811_2.png) [@jeanbenoit](https://builder.metamask.io/u/jeanbenoit)\
**Post date:** [March 24, 2026, 10:47am UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/12 "2026-03-24T10:47:07Z")

</div>

@holyyy Thanks ! I have contacted him.

---

<div class="post-metadata">

**Author:** ![yashovardhan](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/yashovardhan/32/1526_2.png) [@yashovardhan](https://builder.metamask.io/u/yashovardhan)\
**Post date:** [March 29, 2026, 1:19pm UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/13 "2026-03-29T13:19:54Z")

</div>

I have raised the issue with the engineering team, we will get back to you after verifying this.

---

<div class="post-metadata">

**Author:** ![yashovardhan](https://yyz1.discourse-cdn.com/flex011/user_avatar/builder.metamask.io/yashovardhan/32/1526_2.png) [@yashovardhan](https://builder.metamask.io/u/yashovardhan)\
**Post date:** [April 13, 2026, 7:48am UTC](https://builder.metamask.io/t/web3auth-v10-breaks-mfa-setup-on-v9/2971/14 "2026-04-13T07:48:34Z")

</div>

This issue has been fixed from our end, please update to the latest sdk and try once again
