Was this article helpful?
Thanks for your feedback
Two-factor authentication is a way of verifying a user’s identity by using a combination of two different verification methods. It adds an extra layer of security, thereby ensuring that only authorized user(s) can access an account, even if the password has been compromised.
In Contentstack, the two methods used for two-factor authentication are:
To enable two-factor authentication for your account, log in to your Contentstack account, and perform the following steps:
Under Security, scroll down to Two-Factor Authentication. Enter your mobile number, along with the country code, in the given fields. Click Enable 2FA.
You will be prompted to select one of the two available methods for verifying your identity: Authy App and Text Message.
Note: The two options are available for verifying your phone number during the enabling process of two-factor authentication. It does not set the selected method as your preferred method for logging in.
Select Finish. With this step, two-factor authentication is enabled for your account. Subsequently, you will receive a confirmation email at your registered email address.
Log out of your Contentstack account. Log in again by entering your username and password. The next screen will prompt you to enter the security code.
Irrespective of the method selected for verification in Step 3, the login page expects the security code that is visible on the Authy app on your mobile phone. When you launch it, you will see a security token and a timer to indicate the time (in seconds) within which the token will expire. Enter this token on the login page and you will be logged in immediately.
In case you do not have access to the Authy app, you can log in using an SMS verification - but please note this isn’t the preferred method as it’s not as secure. To use this workaround, click the ‘Send me an SMS’ link located below the input field available for entering the security code.
Once two-factor authentication is enabled, the login system (via either Authy or SMS) uses your registered phone number to verify your identity. Consequently, if you do not have access your registered phone number (if you changed it or otherwise), it won’t be possible to log in. Thankfully, Contentstack has a way around this.
Here’s the process to change your verified phone number:
You can disable two-factor authentication in a few steps. However, it is important to note that doing this will remove the additional layer of security from your account. Contentstack highly recommends keeping it enabled.
Here are the steps for disabling two-factor authentication:
Once two-factor authentication is disabled, you will be able to log in to your account by simply entering your registered email address and password.
Additional Resource: It is advisable to change your password regularly to ensure account security. Here are some password requirements that you need to follow. To know more about password security, refer to our Password-related Security section.
Was this article helpful?
Thanks for your feedback