For the complete documentation index, see llms.txt. This page is also available as Markdown.

Set up two-factor authentication

Protect your account with 2FA for an additional layer of security.

Overview

Two-factor authentication (2FA) adds an additional verification step when signing in to your Caspen workspace.

Instead of logging in with just an email and password, users must also enter a one-time verification code generated by an authenticator app on their device.

This means that even if your password is compromised or stolen, no one can access your account without the code generated by the authenticator app on your device.


How does 2FA work?

2FA is configured at the workspace level by the Account Owner. Once enabled, all team members must set up and use 2FA to access the workspace.

2FA works by generating one-time verification codes through an authenticator app on your device. During setup, you will scan a unique QR code, which securely links the authenticator app to your account. After setup, the app can continue generating verification codes without an internet connection.

Once you have set up 2FA, you will be asked to provide a code generated by your authenticator app each time you sign in. When logging in to Caspen, you will need to enter your email address and password, as well as a one-time verification code generated by the authenticator app on your chosen device.


Before you begin

To set up 2FA, you will need an authenticator app installed on your device. Popular options include Google Authenticator, Microsoft Authenticator, 2FAS, and Bitwarden Authenticator. We recommend choosing an authenticator app that is widely recognized and has a strong track record.

Once installed, you'll be able to scan a QR code to connect the app to your Caspen account and generate verification codes for sign-in.

We recommend using a dedicated authenticator app rather than storing your passwords and verification codes in the same application, as keeping them separate provides an additional layer of security.


Enable 2FA for your workspace

Enabling 2FA for your workspace makes it mandatory for all new and existing users to set up and use 2FA when accessing the workspace.

  1. Navigate to Settings → Security.

  2. If 2FA is not already enabled on your account, click Enable now.

  3. Download and install an authenticator app if you haven't already done so.

  4. Open the authenticator app and scan the QR code displayed in Caspen.

  5. Enter the 6-digit verification code generated by the authenticator app.

  6. Click Enable to complete the setup of 2FA on your account.

  7. Return to the Security page. Once your personal 2FA setup is complete, the warning message will be removed and the Enable 2FA button will become available.

  8. Click Enable 2FA to enable two-factor authentication for all users in the workspace.

After this is enabled, users who have not yet set up 2FA will be prompted to do so the next time they sign in to their workspace.

You can monitor adoption from the Users page. A user's 2FA status will show Enabled once they have completed setup, or Disabled if they have not yet configured 2FA.


Enable 2FA for your account

For team members who are not account owners, the owner of your workspace can enable 2FA, after which you will be required to set up 2FA for your own account.

New users will be prompted to set up 2FA when they sign in for the first time. Existing users will be prompted to enable 2FA from within their account or the next time they sign in if they have logged out.

To enable 2FA for your account:

  1. From the bottom-left corner of the navigation menu, click your profile picture → My account.

  2. Navigate to the Security tab.

  3. Under Two-factor authentication (2FA), click Enable.

  4. Follow the setup instructions in Caspen to add your Caspen account to the app:

  • Download an authenticator app (if you haven't already).

  • Open the authenticator app and scan the QR code displayed in Caspen.

  • Enter the 6-digit authentication code from the authenticator app.

  1. Click Enable.

  2. Once enabled, a 2FA status of Enabled will appear next to your name in the user list.

You're now set up to use 2FA the next time you log in to Caspen. You'll need access to your authenticator app each time you sign in to Caspen. Make sure the phone it is installed on is available when logging in.


Resetting 2FA for a team member (account owners)

As an Account Owner, you can reset 2FA for any user in your workspace without needing to contact support.

To reset 2FA:

  1. Go to Settings → Users.

  2. Find the user whose 2FA you want to reset.

  3. Click Actions → Reset 2FA.

Once reset, the user's existing 2FA configuration will be removed. The next time they access their account (or immediately, if they are currently logged in and need to re-authenticate), they will be required to set up 2FA again before they can continue using the platform.


Frequently asked questions

The code from my authenticator app isn't being accepted.

If the authentication code generated by your authenticator app isn't working, first check that you've entered the code correctly and that you're using the most recent code displayed in the app.

For security reasons, authenticator apps generate a new code every 30 seconds. If a code has expired, wait for the next code to appear and try again.

Some authenticator apps display the code with a space after the first three digits (for example, 123 456). When entering the code, enter all six digits without the space.

If you're still having trouble, make sure your device's date and time are set to update automatically. An incorrect device time can cause valid authentication codes to be rejected.

I've set up 2FA, but it's not working. What should I do?

If you're an Account Owner and your 2FA isn't working, please contact the Caspen support team.

If you're any another type of user, contact your Account Owner and ask them to reset your 2FA.

What should I do if I got a new phone and I can no longer access the authenticator app on my old phone?

If you have moved to a new phone and can no longer access the authenticator app on your previous device, you will need to contact your Account Owner and ask them to reset your 2FA.

Once your 2FA has been reset, you'll be able to set it up again using your new device.

If your previous phone or device has been lost or stolen, we also recommend changing your Caspen password as a precautionary security measure.

I've entered the code from my authenticator app, but it's not working.

Two-factor authentication (2FA) uses time-based security codes. For these codes to be accepted, your device's clock must be accurately synchronized with network time.

If your device's time is incorrect, the code generated by your authenticator app may not match the code expected by our servers, resulting in a login error.

To resolve this issue:

  • Check that your device's date and time settings are correct.

  • Enable Set time automatically (or the equivalent setting on your device).

  • Restart your authenticator app and try again.

Your device only needs to sync its time periodically to remain accurate. You do not need a constant internet connection for 2FA to work once your device's time is correctly configured.

The QR code isn't working. What should I do?

If the QR code isn't being accepted, or you are unable to continue after scanning it, try the following:

  • Make sure you are scanning the QR code from within your authenticator app, not with your phone's default camera app.

  • Try rescanning the QR code.

  • Confirm that your device has an active internet connection during setup.

If the issue continues, close and reopen the authenticator app and try the setup process again.

Last updated