Skip to main content

Multi-Factor Authentication

Multi-factor authentication (MFA) adds a second verification step to VeloDB Cloud console sign-in. It applies to organization members. It does not affect warehouse users that connect over MySQL or JDBC, which authenticate with their own credentials. See Warehouse Users and Roles.

MFA works at two scopes:

  • Account MFA: any member can add and manage a second factor for their own account, whether or not the organization requires it.
  • Organization MFA: an Organization Admin can require every member to use MFA. Members who have not set up a second factor must add one at their next sign-in before accessing the console.

Enforce MFA for your organization​

Only Organization Admins can require MFA for the whole organization.

  1. Log in to the VeloDB Cloud console.
  2. In the upper-left corner, click the organization name to open the Organization Overview page.
  3. In the left navigation pane, click Organization Settings.
  4. Under Access & Security, enable Multi-Factor Authentication.

After you enable it, every member must use a second factor to sign in. Members who have not enrolled MFA must add a method at their next sign-in before they can reach the console. The setting takes effect for the current organization and does not change MFA requirements in other organizations.

Supported methods​

VeloDB Cloud offers two second factors:

  • Authenticator App: use a standard app that generates time-based one-time passwords (TOTP), such as Google Authenticator, Microsoft Authenticator, or Authy. During setup, scan a QR code or enter the displayed setup key, then enter the generated 6-digit code.
  • SMS: a one-time code sent to your phone by text message.

You can enroll one method at a time. The SMS Verification option is available from account settings only when your account already has a phone number.

Set up MFA for your account​

Any member can add a second factor to their own account at any time.

  1. Log in to the VeloDB Cloud console.
  2. In the upper-right corner, click your profile icon to open the account menu, then click Account Settings.
  3. Under Security, find Multi-Factor Authentication and click Add Authentication Method.
  4. Choose Authenticator App or SMS Verification.
  5. Complete setup for the method you chose:
    • Authenticator App: scan the QR code with your authenticator app. If you cannot scan the code, select Trouble scanning? and enter the displayed setup key in the app. Enter the 6-digit code that the app generates, then click Confirm.
    • SMS Verification: request a verification code for the phone number already associated with your account, enter the code that you receive by text message, then click Confirm.

After enrollment, the method appears under Multi-Factor Authentication in Account Settings. VeloDB Cloud requests a verification code the next time you sign in.

Manage your MFA method​

To review your enrolled method, open Account Settings and find Multi-Factor Authentication under Security.

  • Change an SMS phone number: for SMS Verification, click the edit icon next to the masked phone number, complete the identity verification, and enter the new phone number.
  • Remove MFA: click Unenroll, enter a verification code from the enrolled method, then click Confirm. Removing MFA means the account no longer has an enrolled second factor. If your organization requires MFA, you must enroll a method again at the next sign-in.

Warning:

Before removing an authenticator app, make sure that you can complete the verification step. If you no longer have access to the enrolled method, contact VeloDB Cloud Support before changing account access settings.

MFA and SAML single sign-on​

Members who sign in through SAML single sign-on authenticate against your identity provider, so VeloDB Cloud does not add its own MFA challenge for them. To require MFA for SAML users, configure the MFA policy in your identity provider instead.

See also​

  • Members: invite members, assign roles, and manage organization access.
  • SAML Single Sign-On: authenticate members through a corporate identity provider.