TOTP (Two-Factor Authentication)
Overview
Two-Factor Authentication (2FA) adds an extra layer of security to your account by requiring both your password and a time-based one-time password (TOTP) generated by an authenticator app. This guide will walk you through setting up, managing, and using 2FA in Termix.
Prerequisites
Before setting up 2FA, ensure you have:
- A smartphone or device with an authenticator app installed
- A local username and password account, TOTP cannot be used with OIDC.
Recommended Authenticator Apps
- Google Authenticator (iOS/Android)
- Microsoft Authenticator (iOS/Android)
- Authy (iOS/Android/Desktop)
- 1Password (iOS/Android/Desktop)
- Bitwarden (iOS/Android/Desktop)
Setting Up Two-Factor Authentication
Step 1: Initiate Setup
- Navigate to your Profile & Security section
- Click on the Security tab
- Click "Enable Two-Factor Authentication"
Step 2: Scan QR Code
- Termix will display a QR code
- Open your authenticator app and scan the QR code
- Alternatively, you can manually enter the secret key shown below the QR code
Step 3: Verify Setup
- Your authenticator app will generate a 6-digit code
- Enter this code in the verification field
- Click "Verify and Enable"
Step 4: Save Backup Codes
- After successful verification, you'll receive backup codes
- Download or copy these codes
- Each backup code can only be used once
- Click "Complete Setup" to finish
Using Two-Factor Authentication
Daily Login
- Enter your username and password as usual
- When prompted, open your authenticator app
- Enter the 6-digit code displayed in your app
Code Generation
- TOTP codes refresh every 30 seconds
- Each code is valid for a limited time
- If a code expires, wait for the next one to appear
Managing Your 2FA Settings
Viewing Status
- Check the Security tab in your User Profile
- The status will show as "Enabled" with a green shield icon
Disabling 2FA
- Go to the Security tab
- Click on "Disable 2FA"
- Enter either:
- Your account password, OR
- A valid TOTP code from your authenticator app
- Click "Disable Two-Factor Authentication"
Managing Backup Codes
Generate New Backup Codes
If you've lost your existing backup codes:
- Go to the Security tab
- Click on "Backup Codes"
- Enter your password or TOTP code
- Click "Generate New Backup Codes"
- Save the new codes
Download Backup Codes
- Click the "Download" button next to your backup codes
- A text file will be downloaded containing all your codes
- Store this file in a secure location
Backup Codes
What Are Backup Codes?
Backup codes are one-time use codes that allow you to access your account if you:
- Lose your authenticator device
- Can't access your authenticator app
Using Backup Codes
- During login, when prompted for a TOTP code
- Enter one of your backup codes instead of a regular TOTP code