Articles in this section

Supported Authentication Methods

This article details the authentication methods that are configurable within Templafy.

Email Authentication

Overview

  • When email authentication is used, Templafy acts as the Identity Provider.
  • The first time a user signs into Templafy, they will receive an email with a verification link. Once the user clicks on the verification link, they will be redirected to the Templafy Web App and asked to create a password.
    • Users are then able to sign into Templafy using their email address and password.

  Note

A company email domain can be added to the authentication method which allows any user with an email from that domain to sign in.

Details

  • Security: Templafy only stores hashed and salted (encrypted) values of passwords.
  • Lockout Mechanism: Templafy prevents brute force attacks by locking the attempted email address for 5 seconds + a random amount after 2 unsuccessful login attempts. After 10 unsuccessful retries, the attempted email address is blocked for 5 minutes.
  • Password Reset: Can only be done via the registered email address for the account, to prevent theft of credentials.
  • User Personal Data: User first and last name are defined when the user creates an account and are stored in our user management log with the hashed password, the tenant the user belongs to, and the chosen authentication method (email).
  • Multifactor Authentication: Templafy does not support MFA for email authentication.
  • Token: The refresh token that is issued upon a successful authentication is valid for 14 days.
  • Logs: An owner on the Templafy tenant can review logins that have been performed with email authentication.

  Note

It is possible to email invite users to the Templafy tenant even if no email authentication method has been configured. Instead of navigating to the tenant, the associated production environment specific server URL can be accessed.

Single Sign-On (SSO) Authentication

Supported Protocols

Supported Identity Providers

IdP specific implementation guides can be found here.

  • Microsoft Entra ID
  • ADFS
  • OKTA
  • OneLogin
  • Google Workspace
  • Ping Federate
  • CA Single-Sign On (formerly CA SiteMinder)
user federation authentication login login methods
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Article is closed for comments.