On this page
verified_user
Security & Two-Factor Authentication (2FA)
Time-based One-Time Passwords (TOTP), recovery codes, Argon2id key derivation, and session defense
kv-file implements enterprise security standards to protect files stored on self-hosted servers from unauthorized access, offline password cracking, and credential theft.
1. Two-Factor Authentication (TOTP)
Enhance your account security by requiring a 6-digit Time-based One-Time Password (RFC 6238) whenever logging in:
┌─────────────────────────────────────────────────────────────┐
│ 1. Enter Credentials │
│ Username + Argon2id Password │
└──────────────────────────────┬──────────────────────────────┘
│ Credentials Verified
┌──────────────────────────────▼──────────────────────────────┐
│ 2. Two-Factor Challenge │
│ 6-Digit Authenticator Code (or Recovery Key) │
└──────────────────────────────┬──────────────────────────────┘
│ Validated (RFC 6238 TOTP)
┌──────────────────────────────▼──────────────────────────────┐
│ 3. Authenticated Session │
│ Issues 128-Bit Session Token & Cookie │
└─────────────────────────────────────────────────────────────┘Enabling 2FA on Your Account
- Open Settings (gear icon in TitleBar) and navigate to the Account tab.
- Click Enable Two-Factor Authentication to launch the wizard (
TwoFactorSetupModal). - Scan QR Code: Scan the QR code using your preferred authenticator app:
- Google Authenticator
- 1Password / Bitwarden
- Apple Keychain (iOS / macOS)
- Microsoft Authenticator / Authy
- Manual Key: Alternatively, copy the base32 secret key into your authenticator.
- Verification: Enter the 6-digit verification code generated by your app.
- Recovery Codes: Download or copy your 10 one-time recovery backup codes. Store them in a secure vault. If you ever lose access to your authenticator device, recovery codes allow emergency account restoration.
2. Password Hashing: Argon2id
Passwords are never stored in plaintext or with deprecated algorithms like MD5 or SHA-256.
- Algorithm: Argon2id (winner of the Password Hashing Competition).
- GPU & ASIC Resistance: Employs memory-hard and time-hard parameters to render brute-force and dictionary attacks computationally infeasible.
- Unique Salt: Every account password is generated with a cryptographically secure 128-bit random salt.
3. Session Management & Defense
- Opaque Session Tokens: Authentication tokens are high-entropy 128-bit UUIDs stored securely in memory and SQLite.
- Automatic Timeout: Inactive sessions expire according to server policies.
- Single-Click Invalidation: Logging out via the UI or API immediately purges the session token server-side.
- Brute-Force Rate Limiting: Consecutive failed login attempts trigger progressive throttling to defeat credential stuffing bots.
4. 2FA API Endpoints
POST/api/v1/auth/2fa/setup
# Generate a new 2FA secret and QR code URI
curl -X POST http://localhost:8866/api/v1/auth/2fa/setup \
-H "Authorization: Bearer <session-token>"POST/api/v1/auth/2fa/enable
# Verify code and enable 2FA
curl -X POST http://localhost:8866/api/v1/auth/2fa/enable \
-H "Authorization: Bearer <session-token>" \
-H "Content-Type: application/json" \
-d '{"code":"123456"}'