Two-Factor Authentication
Vulnotes supports two-factor authentication (2FA) through an authenticator app using time-based codes (TOTP).
TOTP (Authenticator App)
Use an authenticator app such as Google Authenticator or 1Password.
To enable TOTP:
- Go to Profile > Security
- Enable Authenticator App and confirm your password
- Scan the QR code with your authenticator app
- Open Show Codes and save the backup codes somewhere safe
- Enter the 6-digit verification code to confirm
After setup, local email/password sign-in also asks for a code from the authenticator app.
Enforcing 2FA for all users
Administrators can require 2FA for every user on the instance. Go to Administration > Settings > Security and enable Force 2FA for all accounts.
Existing accounts without 2FA receive a setup reminder and a seven-day grace period. After the deadline, access is restricted until they configure it. Accounts created through server setup or invitations already require Authenticator App setup before using the platform; Air-Gap Workstation is exempt from that automatic requirement.
Recovery
If you lose access to your authenticator app, use a saved backup code at the verification step. Each backup code works once. User Management does not provide an administrator reset for 2FA.
