Version 30.6 by Alex Cotiuga on 2026/07/13 06:59

Hide last authors
Alex Cotiuga 1.18 1 {{velocity}}
2 #set ($discard = $xwiki.ssx.use('PublicWebSite.WebHome'))
Alex Cotiuga 10.1 3
Alex Cotiuga 23.1 4 #set ($mainCapabilityItems = [{
Alex Cotiuga 24.1 5 'title': 'Second verification step',
Alex Cotiuga 23.1 6 'icon': 'key',
Alex Cotiuga 24.1 7 'content': 'Add an additional verification screen after the normal XWiki username and password login.'
Alex Cotiuga 10.1 8 },{
Alex Cotiuga 24.1 9 'title': 'Authenticator app codes',
Alex Cotiuga 23.1 10 'icon': 'mobile',
11 'content': 'Let users verify access with time-based TOTP codes generated by authenticator applications.'
Alex Cotiuga 10.1 12 },{
Alex Cotiuga 23.1 13 'title': 'Recovery and trusted devices',
14 'icon': 'shield',
15 'content': 'Provide backup access with recovery codes and reduce repeated prompts on trusted browsers.'
Alex Cotiuga 10.1 16 }])
17
Alex Cotiuga 23.1 18 #set ($adminExperienceItems = [{
Alex Cotiuga 25.2 19 'title': 'Rollout policy',
Alex Cotiuga 22.5 20 'icon': 'cog',
Alex Cotiuga 25.2 21 'content': 'Make additional verification optional at first or required for all users from the XWiki Administration section.'
Alex Cotiuga 10.1 22 },{
Alex Cotiuga 23.1 23 'title': 'Configuration options',
24 'icon': 'sliders',
25 'content': 'Set the authenticator issuer name, recovery-code count and trusted-device duration.'
Alex Cotiuga 10.1 26 },{
Alex Cotiuga 23.1 27 'title': 'Administration overview',
Alex Cotiuga 22.5 28 'icon': 'table',
Alex Cotiuga 25.2 29 'content': 'Review adoption with summary indicators and a filterable Live Data table.'
Alex Cotiuga 10.1 30 }])
31
Alex Cotiuga 23.1 32 #set ($userExperienceItems = [{
Alex Cotiuga 22.5 33 'title': 'Self-service setup',
34 'icon': 'qrcode',
Alex Cotiuga 25.2 35 'content': 'Users configure the second verification step from their profile by scanning a QR code or entering the setup key manually.'
Alex Cotiuga 10.1 36 },{
Alex Cotiuga 23.1 37 'title': 'Login verification',
38 'icon': 'sign-in',
Alex Cotiuga 25.2 39 'content': 'After the normal login, users enter the verification code generated by their authenticator app.'
Alex Cotiuga 10.1 40 },{
Alex Cotiuga 22.5 41 'title': 'Trusted browser option',
42 'icon': 'desktop',
43 'content': 'Users can trust the current browser for the configured duration after successful verification.'
Alex Cotiuga 10.1 44 }])
45
Alex Cotiuga 23.1 46 #set ($selfServiceItems = [{
47 'title': 'Recovery codes',
Alex Cotiuga 22.5 48 'icon': 'life-ring',
Alex Cotiuga 23.1 49 'content': 'Recovery codes provide backup access when a user loses access to the authenticator application.'
Alex Cotiuga 10.1 50 },{
Alex Cotiuga 23.1 51 'title': 'Trusted devices',
52 'icon': 'desktop',
53 'content': 'Trusted devices can be reviewed and removed from the user profile.'
Alex Cotiuga 22.6 54 },{
Alex Cotiuga 23.1 55 'title': 'Profile management',
56 'icon': 'user',
Alex Cotiuga 25.2 57 'content': 'Users can review status, generate recovery codes, manage trusted devices and reset their setup.'
Alex Cotiuga 10.1 58 }])
59
Alex Cotiuga 22.3 60 #set ($adminSupportItems = [{
Alex Cotiuga 25.2 61 'title': 'User status',
Alex Cotiuga 22.5 62 'icon': 'user',
Alex Cotiuga 25.2 63 'content': 'Administrators can open a user profile and check the verification status for that account.'
Alex Cotiuga 22.3 64 },{
Alex Cotiuga 25.2 65 'title': 'Setup reset',
Alex Cotiuga 22.5 66 'icon': 'refresh',
Alex Cotiuga 25.2 67 'content': 'Administrators can reset the setup when a user needs to restart the configuration process.'
Alex Cotiuga 22.3 68 },{
Alex Cotiuga 23.1 69 'title': 'Controlled recovery',
70 'icon': 'unlock-alt',
Alex Cotiuga 25.2 71 'content': 'Resetting the setup removes the authenticator configuration, recovery codes and trusted devices for that user.'
Alex Cotiuga 22.3 72 }])
73
Alex Cotiuga 10.1 74 #set ($rolloutItems = [{
Alex Cotiuga 22.5 75 'title': 'Start with a pilot group',
76 'content': 'Test the extension with administrators or a small user group before enabling it widely.'
Alex Cotiuga 10.1 77 },{
Alex Cotiuga 25.2 78 'title': 'Define the rollout policy',
79 'content': 'Decide whether additional verification should be optional at first or required for all users.'
Alex Cotiuga 10.1 80 },{
Alex Cotiuga 22.5 81 'title': 'Configure recovery options',
82 'content': 'Choose the number of recovery codes and whether trusted devices should be allowed.'
Alex Cotiuga 10.1 83 },{
Alex Cotiuga 23.1 84 'title': 'Inform users',
Alex Cotiuga 25.2 85 'content': 'Explain how users configure the authenticator app, save recovery codes and manage trusted devices.'
Alex Cotiuga 10.1 86 },{
Alex Cotiuga 22.5 87 'title': 'Monitor adoption',
Alex Cotiuga 25.2 88 'content': 'Use the administration overview to identify users who still need to configure protection.'
Alex Cotiuga 10.1 89 }])
90
Alex Cotiuga 1.18 91 {{html clean="false"}}
Alex Cotiuga 1.2 92
Alex Cotiuga 10.1 93 <section class="hero hero-centered" aria-labelledby="product-title">
Alex Cotiuga 1.18 94 <div class="container hero-inner">
95 <div class="hero-kicker">
Alex Cotiuga 1.2 96 <i class="fa fa-lock" aria-hidden="true"></i>
Alex Cotiuga 25.2 97 XWiki 2FA with MFA rollout support
Alex Cotiuga 1.2 98 </div>
99
Alex Cotiuga 25.2 100 <h1 id="product-title">XWiki Two-Factor Authentication</h1>
Alex Cotiuga 1.2 101
Alex Cotiuga 22.5 102 <p class="lead">
Alex Cotiuga 25.2 103 Protect XWiki logins with authenticator app verification, recovery codes,
104 trusted devices and administration controls for a safer rollout.
Alex Cotiuga 22.5 105 </p>
Alex Cotiuga 1.2 106
Alex Cotiuga 30.6 107 <ul class="benefits">
108 <li><strong>Extension from €95/year</strong></li>
109 <li><strong>Basic setup from €150</strong></li>
110 <li>MFA rollout support available</li>
111 </ul>
Alex Cotiuga 30.5 112
Alex Cotiuga 22.5 113 <div class="hero-actions">
114 <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Ask about this extension</a>
Alex Cotiuga 30.2 115 <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
Alex Cotiuga 22.5 116 </div>
Alex Cotiuga 1.18 117 </div>
118 </section>
119
120 <section aria-labelledby="overview-title">
121 <div class="container">
122 <div class="product-layout">
123 <article class="product-summary-card">
Alex Cotiuga 24.1 124 <h2 id="overview-title">Two-factor authentication built into XWiki</h2>
Alex Cotiuga 1.18 125
Alex Cotiuga 22.5 126 <p>
Alex Cotiuga 25.2 127 XWiki Two-Factor Authentication adds an additional verification step to the standard
128 XWiki login flow. Users continue to sign in with their normal username and password,
129 then confirm access with a time-based code from an authenticator application.
Alex Cotiuga 22.5 130 </p>
Alex Cotiuga 1.18 131
Alex Cotiuga 22.5 132 <p>
Alex Cotiuga 25.3 133 The application has evolved beyond a simple login-code screen. It supports global
134 enforcement, recovery codes, trusted devices, user self-service, administrator
135 reset actions and an overview for monitoring adoption.
Alex Cotiuga 22.5 136 </p>
137 </article>
Alex Cotiuga 1.18 138
Alex Cotiuga 22.5 139 <aside class="product-info-card" aria-labelledby="quick-facts-title">
140 <h3 id="quick-facts-title">Quick facts</h3>
141 <ul>
142 <li>Works with the standard XWiki login flow</li>
Alex Cotiuga 23.1 143 <li>Supports TOTP authenticator applications</li>
Alex Cotiuga 25.2 144 <li>Can require additional verification for all users</li>
Alex Cotiuga 22.5 145 <li>Includes one-time recovery codes</li>
Alex Cotiuga 23.1 146 <li>Can remember trusted browsers or devices</li>
Alex Cotiuga 22.5 147 <li>Includes user self-service controls</li>
Alex Cotiuga 23.1 148 <li>Includes an administration overview</li>
Alex Cotiuga 22.5 149 </ul>
150 </aside>
151 </div>
Alex Cotiuga 1.18 152 </div>
153 </section>
154
Alex Cotiuga 23.1 155 <section aria-labelledby="capabilities-title">
Alex Cotiuga 1.18 156 <div class="container">
Alex Cotiuga 24.1 157 <h2 id="capabilities-title">Main capabilities</h2>
Alex Cotiuga 1.18 158
Alex Cotiuga 22.5 159 <p class="section-intro">
Alex Cotiuga 25.2 160 A focused set of authentication protection features for stronger XWiki account security
161 without replacing the familiar login experience.
Alex Cotiuga 22.5 162 </p>
Alex Cotiuga 1.18 163
Alex Cotiuga 22.5 164 <div class="product-feature-grid">
Alex Cotiuga 23.1 165 #foreach ($entry in $mainCapabilityItems)
Alex Cotiuga 22.5 166 <article class="product-feature">
167 <div class="card-heading">
168 <div class="feature-icon">
169 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
170 </div>
171 <h3>$entry.title</h3>
172 </div>
Alex Cotiuga 6.7 173
Alex Cotiuga 22.5 174 <p>$entry.content</p>
175 </article>
176 #end
177 </div>
Alex Cotiuga 10.1 178 </div>
179 </section>
180
Alex Cotiuga 23.1 181 <section class="product-section-muted" aria-labelledby="security-title">
Alex Cotiuga 10.1 182 <div class="container">
Alex Cotiuga 23.1 183 <div class="product-layout">
184 <article class="product-summary-card">
Alex Cotiuga 24.1 185 <h2 id="security-title">Useful for XWiki security and access protection</h2>
Alex Cotiuga 10.1 186
Alex Cotiuga 23.1 187 <p>
188 Many organizations use XWiki to store internal documentation, procedures, operational
Alex Cotiuga 25.2 189 knowledge and business-critical information. Adding an additional authentication factor helps
Alex Cotiuga 23.1 190 reduce the risk of account compromise when a password is exposed or reused.
191 </p>
Alex Cotiuga 1.18 192
Alex Cotiuga 23.1 193 <p>
194 The extension is especially useful for protecting administrator accounts, remote users,
195 private knowledge bases and customer or partner portals.
196 </p>
197 </article>
Alex Cotiuga 8.1 198
Alex Cotiuga 23.1 199 <aside class="product-info-card" aria-labelledby="use-cases-title">
200 <h3 id="use-cases-title">Typical use cases</h3>
201 <ul>
202 <li>Administrator account protection</li>
203 <li>Internal knowledge base security</li>
204 <li>Private documentation platforms</li>
205 <li>Remote user access protection</li>
206 <li>Customer or partner portals</li>
Alex Cotiuga 23.4 207 <li>Security review, MFA rollout and compliance readiness</li>
Alex Cotiuga 23.1 208 </ul>
209 </aside>
Alex Cotiuga 22.5 210 </div>
Alex Cotiuga 10.1 211 </div>
212 </section>
213
Alex Cotiuga 23.1 214 <section aria-labelledby="admin-experience-title">
Alex Cotiuga 10.1 215 <div class="container">
Alex Cotiuga 23.1 216 <h2 id="admin-experience-title">Administrator configuration and monitoring</h2>
Alex Cotiuga 10.1 217
Alex Cotiuga 22.5 218 <p class="section-intro">
Alex Cotiuga 25.2 219 Administrators can configure the policy, define recovery options and monitor adoption
220 from the XWiki Administration section.
Alex Cotiuga 22.5 221 </p>
Alex Cotiuga 10.1 222
Alex Cotiuga 22.5 223 <div class="product-feature-grid">
Alex Cotiuga 23.1 224 #foreach ($entry in $adminExperienceItems)
Alex Cotiuga 22.5 225 <article class="product-feature">
226 <div class="card-heading">
227 <div class="feature-icon">
228 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
229 </div>
230 <h3>$entry.title</h3>
231 </div>
Alex Cotiuga 1.18 232
Alex Cotiuga 22.5 233 <p>$entry.content</p>
234 </article>
235 #end
236 </div>
Alex Cotiuga 10.1 237
238 {{/html}}
239
240 {{gallery}}
Alex Cotiuga 23.1 241 [[image:mfa-admin-configuration.png]]
Alex Cotiuga 10.1 242 [[image:mfa-admin-overview.png]]
Alex Cotiuga 17.2 243 [[image:mfa-admin-full.png]]
Alex Cotiuga 10.1 244 {{/gallery}}
245
246 {{html clean="false"}}
247
Alex Cotiuga 22.5 248 <p class="product-gallery-caption">
Alex Cotiuga 25.2 249 Administration screens for configuring the policy and reviewing adoption across users.
Alex Cotiuga 22.5 250 </p>
Alex Cotiuga 7.2 251 </div>
252 </section>
253
Alex Cotiuga 23.1 254 <section class="product-section-muted" aria-labelledby="user-experience-title">
Alex Cotiuga 6.11 255 <div class="container">
Alex Cotiuga 23.1 256 <h2 id="user-experience-title">User setup and login verification</h2>
Alex Cotiuga 10.1 257
Alex Cotiuga 22.5 258 <p class="section-intro">
Alex Cotiuga 25.2 259 Users can configure the authenticator app from their profile or during the enforced setup flow,
260 then verify future logins with a generated code.
Alex Cotiuga 22.5 261 </p>
Alex Cotiuga 10.1 262
Alex Cotiuga 22.5 263 <div class="product-feature-grid">
Alex Cotiuga 23.1 264 #foreach ($entry in $userExperienceItems)
Alex Cotiuga 22.5 265 <article class="product-feature">
266 <div class="card-heading">
267 <div class="feature-icon">
268 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
269 </div>
270 <h3>$entry.title</h3>
271 </div>
Alex Cotiuga 10.1 272
Alex Cotiuga 22.5 273 <p>$entry.content</p>
274 </article>
275 #end
276 </div>
Alex Cotiuga 10.1 277
278 {{/html}}
279
280 {{gallery}}
281 [[image:mfa-user-setup-qr.png]]
Alex Cotiuga 15.2 282 [[image:mfa-login-verification-setup.png]]
283 [[image:mfa-login-verification-code.png]]
Alex Cotiuga 10.1 284 {{/gallery}}
285
286 {{html clean="false"}}
287
Alex Cotiuga 22.5 288 <p class="product-gallery-caption">
Alex Cotiuga 25.2 289 User setup, enforced configuration and login verification screens.
Alex Cotiuga 22.5 290 </p>
Alex Cotiuga 10.1 291 </div>
292 </section>
293
Alex Cotiuga 23.1 294 <section aria-labelledby="self-service-title">
Alex Cotiuga 10.1 295 <div class="container">
Alex Cotiuga 24.1 296 <h2 id="self-service-title">Recovery codes and trusted devices</h2>
Alex Cotiuga 10.1 297
Alex Cotiuga 22.5 298 <p class="section-intro">
Alex Cotiuga 23.1 299 Recovery codes and trusted devices help balance stronger access protection with a smoother user experience.
Alex Cotiuga 22.5 300 </p>
Alex Cotiuga 10.1 301
Alex Cotiuga 22.5 302 <div class="product-feature-grid">
Alex Cotiuga 23.1 303 #foreach ($entry in $selfServiceItems)
Alex Cotiuga 22.5 304 <article class="product-feature">
305 <div class="card-heading">
306 <div class="feature-icon">
307 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
308 </div>
309 <h3>$entry.title</h3>
310 </div>
Alex Cotiuga 10.1 311
Alex Cotiuga 22.5 312 <p>$entry.content</p>
313 </article>
314 #end
315 </div>
Alex Cotiuga 10.1 316
317 {{/html}}
318
319 {{gallery}}
Alex Cotiuga 23.1 320 [[image:mfa-user-profile-overview.png]]
Alex Cotiuga 22.2 321 [[image:mfa-recovery-codes-not-generated.png]]
322 [[image:mfa-recovery-codes-generated.png]]
Alex Cotiuga 10.1 323 [[image:mfa-trusted-devices.png]]
Alex Cotiuga 22.2 324 [[image:mfa-user-profile-full.png]]
Alex Cotiuga 10.1 325 {{/gallery}}
326
327 {{html clean="false"}}
328
Alex Cotiuga 22.5 329 <p class="product-gallery-caption">
Alex Cotiuga 25.2 330 User profile screens for recovery codes, trusted devices and self-service management.
Alex Cotiuga 22.5 331 </p>
Alex Cotiuga 10.1 332 </div>
333 </section>
334
Alex Cotiuga 22.3 335 <section class="product-section-muted" aria-labelledby="admin-support-title">
Alex Cotiuga 10.1 336 <div class="container">
Alex Cotiuga 22.3 337 <h2 id="admin-support-title">Administrator support and user recovery</h2>
338
Alex Cotiuga 22.5 339 <p class="section-intro">
Alex Cotiuga 25.2 340 Administrators can help users recover from lost devices or restart setup when needed.
Alex Cotiuga 22.5 341 </p>
Alex Cotiuga 22.3 342
Alex Cotiuga 22.5 343 <div class="product-feature-grid">
344 #foreach ($entry in $adminSupportItems)
345 <article class="product-feature">
346 <div class="card-heading">
347 <div class="feature-icon">
348 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
349 </div>
350 <h3>$entry.title</h3>
351 </div>
Alex Cotiuga 22.3 352
Alex Cotiuga 22.5 353 <p>$entry.content</p>
354 </article>
355 #end
356 </div>
Alex Cotiuga 22.3 357
358 {{/html}}
359
360 {{gallery}}
361 [[image:mfa-admin-user-management.png]]
362 {{/gallery}}
363
364 {{html clean="false"}}
365
Alex Cotiuga 22.5 366 <p class="product-gallery-caption">
Alex Cotiuga 25.2 367 Administrator view for checking and resetting a user setup.
Alex Cotiuga 22.5 368 </p>
Alex Cotiuga 22.3 369 </div>
370 </section>
371
Alex Cotiuga 25.2 372 <section aria-labelledby="faq-title">
Alex Cotiuga 22.3 373 <div class="container">
Alex Cotiuga 25.2 374 <h2 id="faq-title">Frequently asked questions</h2>
375
376 <p class="section-intro">
377 Common questions about how the extension works, how users configure it and how administrators can manage rollout and recovery.
378 </p>
379
380 <div class="resource-content">
381 <details class="resource-faq-item">
382 <summary>Does this extension replace the standard XWiki login?</summary>
383 <p>
384 No. Users still sign in with their normal XWiki username and password. The extension adds
385 an additional verification step after the standard login check.
386 </p>
387 </details>
388
389 <details class="resource-faq-item">
390 <summary>Which verification method is used?</summary>
391 <p>
392 Users verify access with time-based codes generated by an authenticator application.
393 The setup page provides a QR code and a manual setup key.
394 </p>
395 </details>
396
397 <details class="resource-faq-item">
398 <summary>Can the second verification step be required for all users?</summary>
399 <p>
400 Yes. Administrators can make the verification step optional or required for all users
401 from the XWiki Administration section.
402 </p>
403 </details>
404
405 <details class="resource-faq-item">
406 <summary>What happens if a user loses access to the authenticator app?</summary>
407 <p>
408 Recovery codes can provide backup access when enabled. Administrators can also reset
409 the user setup so the configuration process can be restarted.
410 </p>
411 </details>
412
413 <details class="resource-faq-item">
414 <summary>Can trusted browsers or devices be disabled?</summary>
415 <p>
416 Yes. Administrators can configure how long trusted devices remain valid. Setting the
417 trusted-device duration to 0 disables this option.
418 </p>
419 </details>
420
421 <details class="resource-faq-item">
422 <summary>Is this only a basic 2FA login-code screen?</summary>
423 <p>
424 No. The main login mechanism is two-factor authentication, but the application also includes
425 features needed for a safer organization-wide rollout: enforcement policy, recovery codes,
426 trusted devices, user self-service, administrator monitoring and administrator reset actions.
427 </p>
428 </details>
429
430 <details class="resource-faq-item">
431 <summary>Is this enough for compliance on its own?</summary>
432 <p>
433 No. This extension provides an important access-protection control, but it should be part
434 of a broader security and compliance approach that includes permissions, upgrades,
435 infrastructure, monitoring and operational procedures.
436 </p>
437 </details>
438 </div>
439 </div>
440 </section>
441
442 <section class="product-section-muted" aria-labelledby="rollout-title">
443 <div class="container">
Alex Cotiuga 8.1 444 <div class="product-layout">
445 <article class="product-summary-card">
Alex Cotiuga 24.1 446 <h2 id="rollout-title">Rollout recommendations</h2>
Alex Cotiuga 6.11 447
Alex Cotiuga 22.5 448 <p>
Alex Cotiuga 25.2 449 For a smooth rollout, start with a small administrator or pilot group before requiring
450 the additional verification step for everyone. This helps validate the configuration,
451 prepare user communication and reduce support issues.
Alex Cotiuga 22.5 452 </p>
Alex Cotiuga 6.11 453
Alex Cotiuga 22.5 454 <ol class="process-list">
455 #foreach ($entry in $rolloutItems)
456 <li>
457 <strong>$entry.title</strong>
458 $entry.content
459 </li>
460 #end
461 </ol>
462 </article>
Alex Cotiuga 6.11 463
Alex Cotiuga 22.5 464 <aside class="product-info-card" aria-labelledby="planning-title">
465 <h3 id="planning-title">Useful information before installation</h3>
Alex Cotiuga 10.1 466
Alex Cotiuga 22.5 467 <p class="product-card-note">
468 These details help evaluate compatibility, rollout scope and configuration options.
469 </p>
Alex Cotiuga 8.1 470
Alex Cotiuga 22.5 471 <ul>
472 <li>XWiki version</li>
473 <li>Single wiki or wiki farm with subwikis</li>
474 <li>Current authentication setup</li>
Alex Cotiuga 25.2 475 <li>Optional or required rollout policy</li>
Alex Cotiuga 22.5 476 <li>Trusted-device policy</li>
477 <li>Recovery-code policy</li>
478 <li>Rollout communication needs</li>
479 </ul>
480 </aside>
481 </div>
Alex Cotiuga 7.2 482 </div>
483 </section>
484
Alex Cotiuga 1.18 485 <section class="cta-section" aria-labelledby="cta-title">
486 <div class="container">
487 <div class="cta-panel">
Alex Cotiuga 24.1 488 <h2 id="cta-title">Interested in using this extension?</h2>
Alex Cotiuga 10.1 489
Alex Cotiuga 22.5 490 <p>
Alex Cotiuga 25.2 491 Send a short message with your XWiki version, current authentication setup and rollout goal.
Alex Cotiuga 22.5 492 </p>
Alex Cotiuga 10.1 493
Alex Cotiuga 22.5 494 <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Contact Agnease</a>
Alex Cotiuga 30.3 495 <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
Alex Cotiuga 22.5 496 </div>
Alex Cotiuga 1.18 497 </div>
498 </section>
499
500 {{/html}}
501 {{/velocity}}