Account security
Two-factor authentication at sign-in, recovery codes, and re-verification before privileged actions.
Confluye protects your account with an authenticator app (TOTP) and one-time recovery codes. Two separate checks use them, and it helps to know which one you are looking at.
| Check | When it runs | Who it applies to |
|---|---|---|
| Sign-in verification | Every time you sign in | Anyone enrolled in two-factor authentication |
| Re-verification (step-up) | Before privileged organization or workspace actions, if more than 15 minutes have passed since your last verification | Organization Admins and Owners |
Enrolling
Go to Settings → Security, then follow Set up an authenticator app. You will:
- Scan the QR code (or paste the setup key) into an authenticator app.
- Enter a six-digit code to confirm the app is working.
- Save your recovery codes. They are shown once and cannot be retrieved later.
Enrollment requires that you signed in recently. If you are asked to sign in again first, that is why.
Signing in once enrolled
After you enter your password — or finish signing in with Google, GitHub, or Microsoft — Confluye asks for a second factor before your session starts:
- Authenticator code — the current six-digit code from your app.
- Recovery code — one of the codes you saved at enrollment. Each one works only once.
Until you enter a valid code, no session exists. Closing the tab at this point leaves you signed out, and the prompt expires after 10 minutes, after which you simply sign in again.
Repeated wrong codes are rate limited. If you are locked out, wait for the period stated in the message before trying again.
Re-verification before privileged actions
Organization Admins and Owners are asked to verify again — on Settings → Security, under Renew MFA verification — before actions such as managing API keys, credentials, integrations, data export, or workspace membership.
This is not a sign-in problem. It means your session is valid but your last verification is more than 15 minutes old. Enter a current code and continue where you left off.
In Approvals, Verify MFA opens a dialog on the same page. Enter your authenticator or unused recovery code there; your unsaved reason, acknowledgement and governance form stay open. An invalid code stays in the dialog for retry. Cancel, Escape and the close button dismiss it without submitting the form; dismissal is disabled while verification is in progress. Successful verification refreshes access, but never repeats a policy change, review decision or activation automatically. Review your draft and explicitly submit it when ready.
If you have not enrolled, the dialog also offers authenticator setup and one-time recovery codes. Save those codes before continuing. If your primary sign-in is too old for enrollment, a full sign-out and sign-in is still required: close the dialog and save your work first, because signing out reloads the page.
The workflow inspector uses the same dialog when Run deployed step needs recent MFA. The destination and deployed version remain selected. After verification, review and confirm the live step again; entering the code does not execute it automatically. Live steps require Admin or Owner execution access. Other sensitive-action screens still use Settings → Security.
Recovery codes
- Each code works once. Used codes are marked spent immediately.
- Generate a fresh set from Settings → Security if you are running low. Generating a new set invalidates the old one.
- Store them somewhere separate from the device holding your authenticator app.
Lost your authenticator and your recovery codes
Contact support to begin privileged recovery. It is deliberately slow, because it is the one path that bypasses your second factor:
- All of your sessions are revoked.
- Pre-established owners are notified.
- Two independent approvals are required.
- A waiting period of at least 24 hours applies before access is restored.
