Version 30.5 by Alex Cotiuga on 2026/07/13 06:57

Hide last authors
Alex Cotiuga 1.18 1 {{velocity}}
2 #set ($discard = $xwiki.ssx.use('PublicWebSite.WebHome'))
Alex Cotiuga 10.1 3
Alex Cotiuga 23.1 4 #set ($mainCapabilityItems = [{
Alex Cotiuga 24.1 5 'title': 'Second verification step',
Alex Cotiuga 23.1 6 'icon': 'key',
Alex Cotiuga 24.1 7 'content': 'Add an additional verification screen after the normal XWiki username and password login.'
Alex Cotiuga 10.1 8 },{
Alex Cotiuga 24.1 9 'title': 'Authenticator app codes',
Alex Cotiuga 23.1 10 'icon': 'mobile',
11 'content': 'Let users verify access with time-based TOTP codes generated by authenticator applications.'
Alex Cotiuga 10.1 12 },{
Alex Cotiuga 23.1 13 'title': 'Recovery and trusted devices',
14 'icon': 'shield',
15 'content': 'Provide backup access with recovery codes and reduce repeated prompts on trusted browsers.'
Alex Cotiuga 10.1 16 }])
17
Alex Cotiuga 23.1 18 #set ($adminExperienceItems = [{
Alex Cotiuga 25.2 19 'title': 'Rollout policy',
Alex Cotiuga 22.5 20 'icon': 'cog',
Alex Cotiuga 25.2 21 'content': 'Make additional verification optional at first or required for all users from the XWiki Administration section.'
Alex Cotiuga 10.1 22 },{
Alex Cotiuga 23.1 23 'title': 'Configuration options',
24 'icon': 'sliders',
25 'content': 'Set the authenticator issuer name, recovery-code count and trusted-device duration.'
Alex Cotiuga 10.1 26 },{
Alex Cotiuga 23.1 27 'title': 'Administration overview',
Alex Cotiuga 22.5 28 'icon': 'table',
Alex Cotiuga 25.2 29 'content': 'Review adoption with summary indicators and a filterable Live Data table.'
Alex Cotiuga 10.1 30 }])
31
Alex Cotiuga 23.1 32 #set ($userExperienceItems = [{
Alex Cotiuga 22.5 33 'title': 'Self-service setup',
34 'icon': 'qrcode',
Alex Cotiuga 25.2 35 'content': 'Users configure the second verification step from their profile by scanning a QR code or entering the setup key manually.'
Alex Cotiuga 10.1 36 },{
Alex Cotiuga 23.1 37 'title': 'Login verification',
38 'icon': 'sign-in',
Alex Cotiuga 25.2 39 'content': 'After the normal login, users enter the verification code generated by their authenticator app.'
Alex Cotiuga 10.1 40 },{
Alex Cotiuga 22.5 41 'title': 'Trusted browser option',
42 'icon': 'desktop',
43 'content': 'Users can trust the current browser for the configured duration after successful verification.'
Alex Cotiuga 10.1 44 }])
45
Alex Cotiuga 23.1 46 #set ($selfServiceItems = [{
47 'title': 'Recovery codes',
Alex Cotiuga 22.5 48 'icon': 'life-ring',
Alex Cotiuga 23.1 49 'content': 'Recovery codes provide backup access when a user loses access to the authenticator application.'
Alex Cotiuga 10.1 50 },{
Alex Cotiuga 23.1 51 'title': 'Trusted devices',
52 'icon': 'desktop',
53 'content': 'Trusted devices can be reviewed and removed from the user profile.'
Alex Cotiuga 22.6 54 },{
Alex Cotiuga 23.1 55 'title': 'Profile management',
56 'icon': 'user',
Alex Cotiuga 25.2 57 'content': 'Users can review status, generate recovery codes, manage trusted devices and reset their setup.'
Alex Cotiuga 10.1 58 }])
59
Alex Cotiuga 22.3 60 #set ($adminSupportItems = [{
Alex Cotiuga 25.2 61 'title': 'User status',
Alex Cotiuga 22.5 62 'icon': 'user',
Alex Cotiuga 25.2 63 'content': 'Administrators can open a user profile and check the verification status for that account.'
Alex Cotiuga 22.3 64 },{
Alex Cotiuga 25.2 65 'title': 'Setup reset',
Alex Cotiuga 22.5 66 'icon': 'refresh',
Alex Cotiuga 25.2 67 'content': 'Administrators can reset the setup when a user needs to restart the configuration process.'
Alex Cotiuga 22.3 68 },{
Alex Cotiuga 23.1 69 'title': 'Controlled recovery',
70 'icon': 'unlock-alt',
Alex Cotiuga 25.2 71 'content': 'Resetting the setup removes the authenticator configuration, recovery codes and trusted devices for that user.'
Alex Cotiuga 22.3 72 }])
73
Alex Cotiuga 10.1 74 #set ($rolloutItems = [{
Alex Cotiuga 22.5 75 'title': 'Start with a pilot group',
76 'content': 'Test the extension with administrators or a small user group before enabling it widely.'
Alex Cotiuga 10.1 77 },{
Alex Cotiuga 25.2 78 'title': 'Define the rollout policy',
79 'content': 'Decide whether additional verification should be optional at first or required for all users.'
Alex Cotiuga 10.1 80 },{
Alex Cotiuga 22.5 81 'title': 'Configure recovery options',
82 'content': 'Choose the number of recovery codes and whether trusted devices should be allowed.'
Alex Cotiuga 10.1 83 },{
Alex Cotiuga 23.1 84 'title': 'Inform users',
Alex Cotiuga 25.2 85 'content': 'Explain how users configure the authenticator app, save recovery codes and manage trusted devices.'
Alex Cotiuga 10.1 86 },{
Alex Cotiuga 22.5 87 'title': 'Monitor adoption',
Alex Cotiuga 25.2 88 'content': 'Use the administration overview to identify users who still need to configure protection.'
Alex Cotiuga 10.1 89 }])
90
Alex Cotiuga 1.18 91 {{html clean="false"}}
Alex Cotiuga 1.2 92
Alex Cotiuga 10.1 93 <section class="hero hero-centered" aria-labelledby="product-title">
Alex Cotiuga 1.18 94 <div class="container hero-inner">
95 <div class="hero-kicker">
Alex Cotiuga 1.2 96 <i class="fa fa-lock" aria-hidden="true"></i>
Alex Cotiuga 25.2 97 XWiki 2FA with MFA rollout support
Alex Cotiuga 1.2 98 </div>
99
Alex Cotiuga 25.2 100 <h1 id="product-title">XWiki Two-Factor Authentication</h1>
Alex Cotiuga 1.2 101
Alex Cotiuga 22.5 102 <p class="lead">
Alex Cotiuga 25.2 103 Protect XWiki logins with authenticator app verification, recovery codes,
104 trusted devices and administration controls for a safer rollout.
Alex Cotiuga 22.5 105 </p>
Alex Cotiuga 1.2 106
Alex Cotiuga 30.5 107 <div class="product-card-kicker">
108 <i class="fa fa-tag" aria-hidden="true"></i>
109 Extension from €95/year · Basic setup from €150
110 </div>
111
Alex Cotiuga 22.5 112 <div class="hero-actions">
113 <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Ask about this extension</a>
Alex Cotiuga 30.2 114 <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
Alex Cotiuga 22.5 115 </div>
Alex Cotiuga 1.18 116 </div>
117 </section>
118
119 <section aria-labelledby="overview-title">
120 <div class="container">
121 <div class="product-layout">
122 <article class="product-summary-card">
Alex Cotiuga 24.1 123 <h2 id="overview-title">Two-factor authentication built into XWiki</h2>
Alex Cotiuga 1.18 124
Alex Cotiuga 22.5 125 <p>
Alex Cotiuga 25.2 126 XWiki Two-Factor Authentication adds an additional verification step to the standard
127 XWiki login flow. Users continue to sign in with their normal username and password,
128 then confirm access with a time-based code from an authenticator application.
Alex Cotiuga 22.5 129 </p>
Alex Cotiuga 1.18 130
Alex Cotiuga 22.5 131 <p>
Alex Cotiuga 25.3 132 The application has evolved beyond a simple login-code screen. It supports global
133 enforcement, recovery codes, trusted devices, user self-service, administrator
134 reset actions and an overview for monitoring adoption.
Alex Cotiuga 22.5 135 </p>
136 </article>
Alex Cotiuga 1.18 137
Alex Cotiuga 22.5 138 <aside class="product-info-card" aria-labelledby="quick-facts-title">
139 <h3 id="quick-facts-title">Quick facts</h3>
140 <ul>
141 <li>Works with the standard XWiki login flow</li>
Alex Cotiuga 23.1 142 <li>Supports TOTP authenticator applications</li>
Alex Cotiuga 25.2 143 <li>Can require additional verification for all users</li>
Alex Cotiuga 22.5 144 <li>Includes one-time recovery codes</li>
Alex Cotiuga 23.1 145 <li>Can remember trusted browsers or devices</li>
Alex Cotiuga 22.5 146 <li>Includes user self-service controls</li>
Alex Cotiuga 23.1 147 <li>Includes an administration overview</li>
Alex Cotiuga 22.5 148 </ul>
149 </aside>
150 </div>
Alex Cotiuga 1.18 151 </div>
152 </section>
153
Alex Cotiuga 23.1 154 <section aria-labelledby="capabilities-title">
Alex Cotiuga 1.18 155 <div class="container">
Alex Cotiuga 24.1 156 <h2 id="capabilities-title">Main capabilities</h2>
Alex Cotiuga 1.18 157
Alex Cotiuga 22.5 158 <p class="section-intro">
Alex Cotiuga 25.2 159 A focused set of authentication protection features for stronger XWiki account security
160 without replacing the familiar login experience.
Alex Cotiuga 22.5 161 </p>
Alex Cotiuga 1.18 162
Alex Cotiuga 22.5 163 <div class="product-feature-grid">
Alex Cotiuga 23.1 164 #foreach ($entry in $mainCapabilityItems)
Alex Cotiuga 22.5 165 <article class="product-feature">
166 <div class="card-heading">
167 <div class="feature-icon">
168 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
169 </div>
170 <h3>$entry.title</h3>
171 </div>
Alex Cotiuga 6.7 172
Alex Cotiuga 22.5 173 <p>$entry.content</p>
174 </article>
175 #end
176 </div>
Alex Cotiuga 10.1 177 </div>
178 </section>
179
Alex Cotiuga 23.1 180 <section class="product-section-muted" aria-labelledby="security-title">
Alex Cotiuga 10.1 181 <div class="container">
Alex Cotiuga 23.1 182 <div class="product-layout">
183 <article class="product-summary-card">
Alex Cotiuga 24.1 184 <h2 id="security-title">Useful for XWiki security and access protection</h2>
Alex Cotiuga 10.1 185
Alex Cotiuga 23.1 186 <p>
187 Many organizations use XWiki to store internal documentation, procedures, operational
Alex Cotiuga 25.2 188 knowledge and business-critical information. Adding an additional authentication factor helps
Alex Cotiuga 23.1 189 reduce the risk of account compromise when a password is exposed or reused.
190 </p>
Alex Cotiuga 1.18 191
Alex Cotiuga 23.1 192 <p>
193 The extension is especially useful for protecting administrator accounts, remote users,
194 private knowledge bases and customer or partner portals.
195 </p>
196 </article>
Alex Cotiuga 8.1 197
Alex Cotiuga 23.1 198 <aside class="product-info-card" aria-labelledby="use-cases-title">
199 <h3 id="use-cases-title">Typical use cases</h3>
200 <ul>
201 <li>Administrator account protection</li>
202 <li>Internal knowledge base security</li>
203 <li>Private documentation platforms</li>
204 <li>Remote user access protection</li>
205 <li>Customer or partner portals</li>
Alex Cotiuga 23.4 206 <li>Security review, MFA rollout and compliance readiness</li>
Alex Cotiuga 23.1 207 </ul>
208 </aside>
Alex Cotiuga 22.5 209 </div>
Alex Cotiuga 10.1 210 </div>
211 </section>
212
Alex Cotiuga 23.1 213 <section aria-labelledby="admin-experience-title">
Alex Cotiuga 10.1 214 <div class="container">
Alex Cotiuga 23.1 215 <h2 id="admin-experience-title">Administrator configuration and monitoring</h2>
Alex Cotiuga 10.1 216
Alex Cotiuga 22.5 217 <p class="section-intro">
Alex Cotiuga 25.2 218 Administrators can configure the policy, define recovery options and monitor adoption
219 from the XWiki Administration section.
Alex Cotiuga 22.5 220 </p>
Alex Cotiuga 10.1 221
Alex Cotiuga 22.5 222 <div class="product-feature-grid">
Alex Cotiuga 23.1 223 #foreach ($entry in $adminExperienceItems)
Alex Cotiuga 22.5 224 <article class="product-feature">
225 <div class="card-heading">
226 <div class="feature-icon">
227 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
228 </div>
229 <h3>$entry.title</h3>
230 </div>
Alex Cotiuga 1.18 231
Alex Cotiuga 22.5 232 <p>$entry.content</p>
233 </article>
234 #end
235 </div>
Alex Cotiuga 10.1 236
237 {{/html}}
238
239 {{gallery}}
Alex Cotiuga 23.1 240 [[image:mfa-admin-configuration.png]]
Alex Cotiuga 10.1 241 [[image:mfa-admin-overview.png]]
Alex Cotiuga 17.2 242 [[image:mfa-admin-full.png]]
Alex Cotiuga 10.1 243 {{/gallery}}
244
245 {{html clean="false"}}
246
Alex Cotiuga 22.5 247 <p class="product-gallery-caption">
Alex Cotiuga 25.2 248 Administration screens for configuring the policy and reviewing adoption across users.
Alex Cotiuga 22.5 249 </p>
Alex Cotiuga 7.2 250 </div>
251 </section>
252
Alex Cotiuga 23.1 253 <section class="product-section-muted" aria-labelledby="user-experience-title">
Alex Cotiuga 6.11 254 <div class="container">
Alex Cotiuga 23.1 255 <h2 id="user-experience-title">User setup and login verification</h2>
Alex Cotiuga 10.1 256
Alex Cotiuga 22.5 257 <p class="section-intro">
Alex Cotiuga 25.2 258 Users can configure the authenticator app from their profile or during the enforced setup flow,
259 then verify future logins with a generated code.
Alex Cotiuga 22.5 260 </p>
Alex Cotiuga 10.1 261
Alex Cotiuga 22.5 262 <div class="product-feature-grid">
Alex Cotiuga 23.1 263 #foreach ($entry in $userExperienceItems)
Alex Cotiuga 22.5 264 <article class="product-feature">
265 <div class="card-heading">
266 <div class="feature-icon">
267 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
268 </div>
269 <h3>$entry.title</h3>
270 </div>
Alex Cotiuga 10.1 271
Alex Cotiuga 22.5 272 <p>$entry.content</p>
273 </article>
274 #end
275 </div>
Alex Cotiuga 10.1 276
277 {{/html}}
278
279 {{gallery}}
280 [[image:mfa-user-setup-qr.png]]
Alex Cotiuga 15.2 281 [[image:mfa-login-verification-setup.png]]
282 [[image:mfa-login-verification-code.png]]
Alex Cotiuga 10.1 283 {{/gallery}}
284
285 {{html clean="false"}}
286
Alex Cotiuga 22.5 287 <p class="product-gallery-caption">
Alex Cotiuga 25.2 288 User setup, enforced configuration and login verification screens.
Alex Cotiuga 22.5 289 </p>
Alex Cotiuga 10.1 290 </div>
291 </section>
292
Alex Cotiuga 23.1 293 <section aria-labelledby="self-service-title">
Alex Cotiuga 10.1 294 <div class="container">
Alex Cotiuga 24.1 295 <h2 id="self-service-title">Recovery codes and trusted devices</h2>
Alex Cotiuga 10.1 296
Alex Cotiuga 22.5 297 <p class="section-intro">
Alex Cotiuga 23.1 298 Recovery codes and trusted devices help balance stronger access protection with a smoother user experience.
Alex Cotiuga 22.5 299 </p>
Alex Cotiuga 10.1 300
Alex Cotiuga 22.5 301 <div class="product-feature-grid">
Alex Cotiuga 23.1 302 #foreach ($entry in $selfServiceItems)
Alex Cotiuga 22.5 303 <article class="product-feature">
304 <div class="card-heading">
305 <div class="feature-icon">
306 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
307 </div>
308 <h3>$entry.title</h3>
309 </div>
Alex Cotiuga 10.1 310
Alex Cotiuga 22.5 311 <p>$entry.content</p>
312 </article>
313 #end
314 </div>
Alex Cotiuga 10.1 315
316 {{/html}}
317
318 {{gallery}}
Alex Cotiuga 23.1 319 [[image:mfa-user-profile-overview.png]]
Alex Cotiuga 22.2 320 [[image:mfa-recovery-codes-not-generated.png]]
321 [[image:mfa-recovery-codes-generated.png]]
Alex Cotiuga 10.1 322 [[image:mfa-trusted-devices.png]]
Alex Cotiuga 22.2 323 [[image:mfa-user-profile-full.png]]
Alex Cotiuga 10.1 324 {{/gallery}}
325
326 {{html clean="false"}}
327
Alex Cotiuga 22.5 328 <p class="product-gallery-caption">
Alex Cotiuga 25.2 329 User profile screens for recovery codes, trusted devices and self-service management.
Alex Cotiuga 22.5 330 </p>
Alex Cotiuga 10.1 331 </div>
332 </section>
333
Alex Cotiuga 22.3 334 <section class="product-section-muted" aria-labelledby="admin-support-title">
Alex Cotiuga 10.1 335 <div class="container">
Alex Cotiuga 22.3 336 <h2 id="admin-support-title">Administrator support and user recovery</h2>
337
Alex Cotiuga 22.5 338 <p class="section-intro">
Alex Cotiuga 25.2 339 Administrators can help users recover from lost devices or restart setup when needed.
Alex Cotiuga 22.5 340 </p>
Alex Cotiuga 22.3 341
Alex Cotiuga 22.5 342 <div class="product-feature-grid">
343 #foreach ($entry in $adminSupportItems)
344 <article class="product-feature">
345 <div class="card-heading">
346 <div class="feature-icon">
347 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
348 </div>
349 <h3>$entry.title</h3>
350 </div>
Alex Cotiuga 22.3 351
Alex Cotiuga 22.5 352 <p>$entry.content</p>
353 </article>
354 #end
355 </div>
Alex Cotiuga 22.3 356
357 {{/html}}
358
359 {{gallery}}
360 [[image:mfa-admin-user-management.png]]
361 {{/gallery}}
362
363 {{html clean="false"}}
364
Alex Cotiuga 22.5 365 <p class="product-gallery-caption">
Alex Cotiuga 25.2 366 Administrator view for checking and resetting a user setup.
Alex Cotiuga 22.5 367 </p>
Alex Cotiuga 22.3 368 </div>
369 </section>
370
Alex Cotiuga 25.2 371 <section aria-labelledby="faq-title">
Alex Cotiuga 22.3 372 <div class="container">
Alex Cotiuga 25.2 373 <h2 id="faq-title">Frequently asked questions</h2>
374
375 <p class="section-intro">
376 Common questions about how the extension works, how users configure it and how administrators can manage rollout and recovery.
377 </p>
378
379 <div class="resource-content">
380 <details class="resource-faq-item">
381 <summary>Does this extension replace the standard XWiki login?</summary>
382 <p>
383 No. Users still sign in with their normal XWiki username and password. The extension adds
384 an additional verification step after the standard login check.
385 </p>
386 </details>
387
388 <details class="resource-faq-item">
389 <summary>Which verification method is used?</summary>
390 <p>
391 Users verify access with time-based codes generated by an authenticator application.
392 The setup page provides a QR code and a manual setup key.
393 </p>
394 </details>
395
396 <details class="resource-faq-item">
397 <summary>Can the second verification step be required for all users?</summary>
398 <p>
399 Yes. Administrators can make the verification step optional or required for all users
400 from the XWiki Administration section.
401 </p>
402 </details>
403
404 <details class="resource-faq-item">
405 <summary>What happens if a user loses access to the authenticator app?</summary>
406 <p>
407 Recovery codes can provide backup access when enabled. Administrators can also reset
408 the user setup so the configuration process can be restarted.
409 </p>
410 </details>
411
412 <details class="resource-faq-item">
413 <summary>Can trusted browsers or devices be disabled?</summary>
414 <p>
415 Yes. Administrators can configure how long trusted devices remain valid. Setting the
416 trusted-device duration to 0 disables this option.
417 </p>
418 </details>
419
420 <details class="resource-faq-item">
421 <summary>Is this only a basic 2FA login-code screen?</summary>
422 <p>
423 No. The main login mechanism is two-factor authentication, but the application also includes
424 features needed for a safer organization-wide rollout: enforcement policy, recovery codes,
425 trusted devices, user self-service, administrator monitoring and administrator reset actions.
426 </p>
427 </details>
428
429 <details class="resource-faq-item">
430 <summary>Is this enough for compliance on its own?</summary>
431 <p>
432 No. This extension provides an important access-protection control, but it should be part
433 of a broader security and compliance approach that includes permissions, upgrades,
434 infrastructure, monitoring and operational procedures.
435 </p>
436 </details>
437 </div>
438 </div>
439 </section>
440
441 <section class="product-section-muted" aria-labelledby="rollout-title">
442 <div class="container">
Alex Cotiuga 8.1 443 <div class="product-layout">
444 <article class="product-summary-card">
Alex Cotiuga 24.1 445 <h2 id="rollout-title">Rollout recommendations</h2>
Alex Cotiuga 6.11 446
Alex Cotiuga 22.5 447 <p>
Alex Cotiuga 25.2 448 For a smooth rollout, start with a small administrator or pilot group before requiring
449 the additional verification step for everyone. This helps validate the configuration,
450 prepare user communication and reduce support issues.
Alex Cotiuga 22.5 451 </p>
Alex Cotiuga 6.11 452
Alex Cotiuga 22.5 453 <ol class="process-list">
454 #foreach ($entry in $rolloutItems)
455 <li>
456 <strong>$entry.title</strong>
457 $entry.content
458 </li>
459 #end
460 </ol>
461 </article>
Alex Cotiuga 6.11 462
Alex Cotiuga 22.5 463 <aside class="product-info-card" aria-labelledby="planning-title">
464 <h3 id="planning-title">Useful information before installation</h3>
Alex Cotiuga 10.1 465
Alex Cotiuga 22.5 466 <p class="product-card-note">
467 These details help evaluate compatibility, rollout scope and configuration options.
468 </p>
Alex Cotiuga 8.1 469
Alex Cotiuga 22.5 470 <ul>
471 <li>XWiki version</li>
472 <li>Single wiki or wiki farm with subwikis</li>
473 <li>Current authentication setup</li>
Alex Cotiuga 25.2 474 <li>Optional or required rollout policy</li>
Alex Cotiuga 22.5 475 <li>Trusted-device policy</li>
476 <li>Recovery-code policy</li>
477 <li>Rollout communication needs</li>
478 </ul>
479 </aside>
480 </div>
Alex Cotiuga 7.2 481 </div>
482 </section>
483
Alex Cotiuga 1.18 484 <section class="cta-section" aria-labelledby="cta-title">
485 <div class="container">
486 <div class="cta-panel">
Alex Cotiuga 24.1 487 <h2 id="cta-title">Interested in using this extension?</h2>
Alex Cotiuga 10.1 488
Alex Cotiuga 22.5 489 <p>
Alex Cotiuga 25.2 490 Send a short message with your XWiki version, current authentication setup and rollout goal.
Alex Cotiuga 22.5 491 </p>
Alex Cotiuga 10.1 492
Alex Cotiuga 22.5 493 <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Contact Agnease</a>
Alex Cotiuga 30.3 494 <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
Alex Cotiuga 22.5 495 </div>
Alex Cotiuga 1.18 496 </div>
497 </section>
498
499 {{/html}}
500 {{/velocity}}