Tillbaka till ändringsloggen
SecurityAccounts·

Two-factor authentication

Protect your account with a code from your authenticator app, so a stolen password is no longer enough to reach your servers, domains, and secrets.

Your Cosmoner account controls servers, DNS records, and secrets. Until now a password was the only thing standing between all of that and whoever happened to have it — reused on another site, phished, or sitting in a breach dump.

You can now add a second step. Go to Account → Security, scan the QR code with any authenticator app (1Password, Bitwarden, Google Authenticator, Authy), and from then on signing in asks for a six-digit code after your password. The same code is asked for whether you sign in to the control panel or anywhere else your account reaches.

A few things we made a point of getting right:

  • Setup can't lock you out. Two-factor authentication only switches on once a code from your app has been accepted. Scan the wrong thing, or close the tab halfway, and your account is exactly as it was.
  • Ten single-use recovery codes, shown once at the end of setup. They are stored encrypted, so we genuinely cannot read them back to you — save them somewhere other than the device running your authenticator app. You can issue a fresh set at any time, which invalidates the old one.
  • "Trust this device for 30 days" skips the code on a browser you use daily. Worth knowing that signing out does not undo it — Account → Security → Revoke all does, on every device at once, which is what you want the day a laptop goes missing.

Turning it off again takes your password and one click.

If you sign in with Continue with GitHub, that route is governed by the second factor on your GitHub account rather than this one — we'd suggest turning 2FA on there too.

Full walkthrough in the two-factor authentication guide.