Security and privacy
Two-factor authentication
Two-factor authentication (2FA, also called MFA) adds a second step to signing in: after your password, or after Google or GitHub, EvoHub asks for a 6-digit code from an authenticator app on your phone. This page explains how to turn it on, how an organization can require it, and how to manage your signed-in devices.
What you need
An authenticator app that supports time-based one-time passwords (TOTP), such as Google Authenticator, Authy, 1Password or Microsoft Authenticator. EvoHub does not send codes by SMS or email.
Turn on two-factor authentication
Open Authentication
Open the avatar menu, choose My Account, then Authentication. Next to Two-factor authentication, select Enable.
Show the QR code
The QR code is hidden so that nobody nearby can scan it. Select Show QR code when you are ready.
From now on, every sign-in to your account asks for a code.
Warning
EvoHub does not currently provide backup codes. Before you finish setup, keep a copy of the setup key somewhere safe, such as your password manager, or add the account to a second device. With the key you can restore the codes on a new phone.
Sign in with a code
- Sign in with your email and password, or with Google or GitHub.
- On the Two-factor authentication screen, enter the current 6-digit code from your app.
The code screen is valid for 5 minutes. If it expires, start the sign-in again. Codes change every 30 seconds; if one is rejected, wait for the next one and check that your phone's clock is set automatically.
Turn off two-factor authentication
Go to My Account → Authentication, select Disable next to Two-factor authentication, enter a current code from your authenticator app and select Disable MFA. A current code is required, so someone who only knows your password cannot turn it off.
If your organization requires two-factor authentication, you will be asked to set it up again the next time you sign in.
If you lose your device
- If you saved the setup key, add it to the authenticator app on your new device and sign in as usual. Then turn 2FA off and on again to get a fresh key.
- Turning 2FA off also needs a code, so being signed in elsewhere does not help on its own; restore the key first.
- If you have neither the key nor a second device, contact support at info@evosync.io from the email address on your account.
Require two-factor authentication for an organization
Administrators can make 2FA mandatory for everyone in an organization.
What happens next:
- Members who already use 2FA notice nothing.
- A member without 2FA is taken through setup the next time they sign in, whether with a password or with Google or GitHub, and enters the organization only after it is done.
- Someone switching into the organization from another one is asked to set up 2FA first.
Review your sessions
My Account → Active Sessions lists every device signed in to your account: browser and operating system, IP address, when it was last seen and when it signed in. Your current device is marked Current session, and the mobile app is marked MOBILE.
To sign a device out, select Revoke and confirm with Revoke Session. Do this for any device you do not recognize, and then change your password.
Sessions also end on their own after a period of inactivity, 7 days by default. Administrators can change this under Organization → Login Policies → Session Timeout.
Related
Was this page helpful?
