Skip to content
All documentation

Two-Factor Authentication

Add time-based one-time passwords (TOTP) and single-use recovery codes to any account, and optionally require them for admins and owners with step-up re-authentication before sensitive actions.

What it is

Two-factor authentication (2FA) requires something you know (your password) plus something you have (a 6-digit code from an authenticator app) to sign in. It follows the industry standard TOTP algorithm (RFC 6238), the same one used by Google Authenticator, 1Password, and Authy.

Two-factor authentication is optional by default. Any account can enable it in Settings to protect their own sign-in. An organization admin can choose to require it for all admins and owners, after which those accounts must enable 2FA before they can use admin features.

Use

  • In Settings, open Two-factor authentication and choose Enable. Scan the QR code with your authenticator app (or enter the manual key), then enter the 6-digit code to confirm.
  • After enabling, save the recovery codes shown once. Each code works a single time and lets you sign in if you lose your authenticator.
  • Signing in with 2FA enabled asks for your password, then a code before the session starts.
  • An org admin can turn on Require two-factor authentication for admins in Settings, Security. When it is on, sensitive admin actions (organization settings, member role changes, user import, and AI model endpoint changes) require a fresh 2FA check within the last 15 minutes. If it has expired, you are asked to re-enter a code.

Setup

No manual setup. The required database columns are added by the standard migration (npm run db:migrate), including the organization-level mfa_required switch (default off). The shared secret and recovery codes are generated server-side.

Security

  • The TOTP secret is encrypted at rest (AES-256-GCM) and returned to you exactly once, at enrollment. It is never stored in plain text.
  • Recovery codes are stored as bcrypt hashes and encrypted at rest; a used code is removed so it cannot be reused.
  • Code checks are timing-safe, single-use per time step (a replay of an already-used code is rejected), and rate-limited with a lockout after repeated failures.
  • When an org requires 2FA, admin and owner accounts must have it enabled and verified before using admin routes, and ownership and role changes re-check it, so a stolen session alone cannot change an organization.