SMS is not suitable for 2FA. SMS messages can show on locked devices, and SIM swap attacks can allow malicious parties access to intercept SMS messages without ever having access to your device.
Additionally, companies often carelessly use phone numbers as both an authentication factor and an account recovery mechanism — a setup this is actually less secure than a password and no phone number. Now I’m sure none of you currently at Mixpanel would do that, but think of your doubtless less-informed future colleagues.
Please support TOTP instead of (or, if you must, in addition to) SMS for 2FA.