Avion Knowledge Base
avion.ioSign inSign up
  • πŸ‘‹Introduction
  • πŸ‘‰Getting started
    • What is Avion?
    • Define your product backbone
    • Scoping and prioritizing your product
    • Creating your release plan
    • Aligning the team
    • Integrating with backlog tools
  • Docs
    • πŸ‘Core concepts
      • Projects
        • Project team
        • Migrating to projects
      • Organizations
        • Invite a member
        • Remove a member
        • Roles
        • Transfer ownership
        • Configure your path
        • Delete your organization
    • πŸš€Story map
      • Story map anatomy
      • Journeys and steps
      • Stories
      • Releases
      • Attachments
      • Tags
      • Personas
      • Labels
      • Dependencies
      • Search and filter
      • Sharing
        • Restricted links
        • Public links
      • Workflow
      • Importing data
        • Import from Excel
          • XLSX import template
        • Import from StoriesOnBoard
      • Exporting data
        • Export to PDF
        • Export to image
        • Export to CSV
        • Export to Excel
      • Rich text editor
        • Keyboard shortcuts
        • Known limitations
      • Keyboard shortcuts
      • Tips
    • 🀝Integrations
      • Backlog tools
        • Set up an integration
          • Authentication
          • Project / board selection
          • Backbone syncing
          • Map story states
          • Additional syncing options
          • Importing data
        • Sync data
          • Pushing
          • Importing
          • Attachments
          • Deleting data
        • Configuration
        • Pause an integration
        • Re-authenticate
        • Remove an integration
        • Maintenance
          • Removing stale webhooks
        • FAQs and troubleshooting
        • Services
          • Jira Cloud
            • Features
            • Set up
            • Permissions required
            • Mapping options
              • Mapping fix versions
            • Epics ~ our thoughts
            • Additional data syncing
              • Mapping custom fields
                • Company-managed projects
                • Team-managed projects
            • Migrating to epic hierarchies
            • Import using JQL
            • FAQs and troubleshooting
              • Required fields
              • Verify webhooks
              • JQL import issues
              • Workflow issues
              • Ghost cards (cards with a dashed border)
              • Limitations
              • Jira Cloud or Jira Server
          • Jira Data Center (Server)
            • Features
            • Set up
              • Creating an application link
            • Permissions required
            • Mapping options
            • Additional data syncing
              • Mapping custom fields
            • Import using JQL
            • FAQs and troubleshooting
              • Required fields
              • Ghost cards (card with a dashed border)
              • Jira Cloud or Jira Server
              • JQL import issues
          • Azure DevOps
            • Features
            • Set up
            • Permissions required
            • Import using WIQL
            • FAQs and troubleshooting
              • Verify webhooks
              • No Azure DevOps accounts were found for your user
              • Problems communicating with Azure DevOps
              • Work items couldn't be imported
              • Show epics in Azure DevOps backlog
              • Import limits
          • Trello
            • Features
            • Set up
            • FAQs and troubleshooting
          • GitHub
            • Features
            • Set up
            • Permissions required
            • FAQs and troubleshooting
              • What types of GitHub Projects are supported?
          • Linear
            • Features
            • Set up
            • Permissions required
            • FAQs and troubleshooting
      • Notifications
        • Slack
          • Set up
          • Configure notification settings
          • Remove Slack
      • Design tools and media
        • Figma
        • Adobe XD
        • Axure
        • Framer X
        • Invision Web & Studio
        • YouTube & Vimeo
      • Embed Avion
        • Confluence
        • Confluence Server
        • Notion
        • Coda
    • πŸ”’Security
      • Single Sign-On (SSO)
        • Setup & Configure SSO
        • Azure AD
        • Google Workspace
        • Okta
        • OpenID Connect
      • Two-factor authentication (2FA)
    • ❓FAQs
      • Attachment file types
    • πŸ’³Billing
      • Plans and pricing
      • Legacy plans
      • Free trials
      • Billing and payments
      • Change your plan
      • Cancel your plan
      • Refunds
      • Startup, student and educational discount
  • Story Mapping Guides
    • How To Story Map β€” A Simple Example
    • Advantages of Story Mapping
    • A Recommended Workflow
Powered by GitBook
On this page
  • About two-factor authentication
  • Configuring two-factor authentication
  • Recovery codes
  • Multiple devices
  1. Docs
  2. Security

Two-factor authentication (2FA)

You can set up your account on Avion to require an authentication code in addition to your password when you sign in

Last updated 1 year ago

About two-factor authentication

Two-factor authentication (2FA) adds an extra layer of security when signing-in to Avion. When you enable 2FA, you must sign in with your email and password and provide another form of authentication that only you know or have access to.

Using 2FA ensures that even if a password is compromised, access to Avion won’t be granted unless the person signing in is verified from their device. We strongly urge you to enable 2FA for the safety of your account, not only on Avion, but on other websites and apps that support 2FA.

Note: Two-factor authentication is not used for sign-in requests when SSO is enabled in your Avion organization

If your company uses an identity provider, you should consider upgrading and configuring instead.

Configuring two-factor authentication

You can configure two-factor authentication using a time-based one-time password (TOTP) application on your mobile or desktop device. Many TOTP apps support the secure backup of your authentication codes in the cloud and can be restored if you lose access to your device.

To configure 2FA:

  1. Head to your Account settings

  2. In the "Two-factor authentication" section, click Enable

  3. Confirm your password

  4. On the QR code step, do one of the following:

    • Scan the QR code with your mobile TOTP app. After scanning, the app will display a six-digit code

    • If you can't scan the QR code, click secret key to copy the code for manual setup in your TOTP app instead

  5. Confirm your six-digit code to finish setup

Recovery codes

Recovery codes are the only way to access your account should you lose your phone or delete your authenticator app. Please note that each code may only be used once. Your recovery codes are provided at the time that you set up 2FA, but you can always find them again in your Account settings.

Don't forget to save a copy of your recovery codes separately for safekeeping. Our support team will not be able to restore access to your account.

Multiple devices

To configure authentication via TOTP on multiple devices, during setup, scan the QR code using each device at the same time or save the "setup key", which is the TOTP secret. If 2FA is already enabled and you want to add another device, you must re-configure your TOTP app from your security settings.

πŸ”’
Single Sign-On