Account & Security
Account security in Fesk covers your password, two-factor authentication, recovery codes, and single sign-on. Everything here lives under Settings → Security and applies to your own login, not the whole workspace.
Changing your password
Go to Settings → Security and use the Change password form. You'll confirm your current password and set a new one (minimum 8 characters). Passwords are verified and stored by the identity provider, not by Fesk directly, so the same rules apply whether you sign in here or through single sign-on.
Two-factor authentication (2FA)
Two-factor authentication adds a one-time code from an authenticator app on top of your password. Once enabled, signing in requires both your password and a fresh 6-digit code, so a leaked password alone can't get into your account.
Fesk uses TOTP (time-based one-time passwords), which works with any standard authenticator app, Google Authenticator, 1Password, Authy, Microsoft Authenticator, and others.
Turning on 2FA
- Go to Settings → Security and click Set up two-factor authentication.
- Scan the QR code with your authenticator app. (Can't scan? Enter the secret key shown next to the code manually.)
- Enter the 6-digit code from the app to confirm.
- Fesk shows your recovery codes: save them now (see below).
Once confirmed, 2FA is active immediately and required at your next sign-in.
Recovery codes
When you enable 2FA, Fesk generates 10 single-use recovery codes. Each one works once in place of an authenticator code, so you can still get in if you lose your phone.
- Save them somewhere safe: a password manager is ideal. They're shown in full only once.
- The Security page shows how many codes you have left.
- Running low or think they leaked? Click Regenerate recovery codes to get a fresh set of 10. Regenerating invalidates the old set.
Signing in with 2FA
After your email and password, Fesk asks for your 6-digit code. Enter the current code from your authenticator app, or use one of your recovery codes if you can't reach the app.
Turning off 2FA
On Settings → Security, choose Disable two-factor authentication. This removes the authenticator factor and your recovery codes. You can re-enroll any time, you'll get a new secret and a new set of recovery codes.
Sign in with Google
Fesk supports Sign in with Google from the sign-in page. Use it to skip the password step entirely, Google handles authentication and returns you to Fesk. If your account was created with an email and password, you can keep using that; single sign-on and password sign-in can coexist for the same email.
Related
- Admins can review security-relevant events across the workspace in the audit logs.
- Managing who has access and what they can do is covered in user management.