{% extends "base.html" %} {% block content %}
{{ icon('shield') }}
Secure your account

Set up your authenticator

All accounts require a password and an authenticator code before accessing the PKI. Add a new time-based account to an authenticator that supports SHA-256.

Account
{{ current_user['username'] }} — {{ settings.organization }}
Setup key
{{ secret }}
Algorithm
SHA-256
Digits / interval
6 digits / 30 seconds

Store a protected backup of this setup key before continuing. There are no recovery codes or automated MFA resets in this version. A password reset does not remove the authenticator requirement.

Enrollment expires after 10 minutes. The setup key is shown only until enrollment is completed.

{% endblock %}