This article details the authentication methods that are configurable within Templafy.
Email Authentication
Overview
- When email authentication is used, Templafy acts as the Identity Provider.
- Email authentication can allow users to sign in with a password, an email verification code, or both, depending on how the authentication method is configured.
- If password sign-in is enabled, users can sign in with their email address and password.
- If email verification code sign-in is enabled, users receive a 6-digit code by email and enter it on the sign-in page. The code expires after 15 minutes.
- When a user activates an account or accepts an invitation, the setup page follows the tenant's Email authentication settings. Passwordless-only users complete their profile without creating a password.
NoteA company email domain can be added to the authentication method which allows any user with an email from that domain to sign in. |
Details
- Security: When passwords are used, Templafy only stores hashed and salted values of passwords. Email verification codes are single-use and are sent to the user's registered email address.
- Lockout Mechanism: Templafy prevents brute force attacks by temporarily locking the attempted email address after repeated unsuccessful sign-in attempts.
- Password Reset: Password reset is only available when password sign-in is enabled and can only be done via the registered email address for the account.
- User Personal Data: User first and last name are defined when the user creates an account and are stored with the tenant the user belongs to and the chosen authentication method.
- Multifactor Authentication: Templafy does not support MFA for email authentication.
- Token: The refresh token that is issued upon a successful authentication is valid for 14 days.
- Logs: An owner on the Templafy tenant can review logins that have been performed with email authentication.
NoteIt is possible to email invite users to the Templafy tenant even if no email authentication method has been configured. Instead of navigating to the tenant, the associated production environment specific server URL can be accessed. |
Single Sign-On (SSO) Authentication
Supported Protocols
Supported Identity Providers
IdP specific implementation guides can be found here.
- Microsoft Entra ID
- ADFS
- OKTA
- OneLogin
- Google Workspace
- Ping Federate
- CA Single-Sign On (formerly CA SiteMinder)
Comments
Article is closed for comments.