Two-factor authentication

User security level (clearance)

A user can change their security level at any time in the account settings in the Authentication section:

  • Weak – ID and password authentication

    Authentication by ID and password. Password recovery by email.

  • Moderate– Hybrid authentication

    Authentication by ID and password. Password recovery by email and SMS code. This level requires users to specify their mobile number including country code.

  • Strong – Two-factor authentication

    Authentication and password recovery by email and SMS code. This level also requires users to specify their mobile number including country code.

Login

If a user has set two-factor authentication, once they enter their email and password, a random 6-digit code is generated and a SMS is sent to the user. The user is redirected to a page where they can enter the code. They can also return to login and have a new code sent.

Users can attempt to log in for three times before they are redirected back to the login page.

The code has a timeout after which it’s considered invalid.

Password recovery

If a user chose two-factor authentication schema for recovery, the user is sent an email with the link to the security code page and an SMS with the security code. Once the user enters the code, they can change their password.