Security & two-factor auth
Turn on two-factor authentication for the owner or every user, how trusted browsers work, what staff see on their next login, and the other account protections Kapda Stock applies.
Two-factor authentication (2FA) asks for a six-digit code from an authenticator app in addition to the password, so a stolen password alone cannot open your business.
Turn on 2FA#
Owner or Admin:
- Open Settings โ ๐ Security โ Two-factor authentication โ Require a one-time code from an authenticator app at login. Off by default.
- Choose On โ An authenticator app is set up, and a 6-digit code is needed when signing in on a new device. You see Two-factor authentication enabled.
- Under Who does it apply to? choose:
- Owner only โ Just your own account. Staff sign in with a password.
- Every user โ Admins, managers and cashiers too โ any of those accounts can reach your data. Each sets up an app on their next login.
Choosing Off โ Logging in needs only an email & password โ turns it off for everyone.
The owner is always covered while 2FA is on, whichever scope is chosen.
What happens at the next login#
For each covered account:
- After the password, the login page shows a QR code: Two-factor authentication keeps your business safe. Scan with Google Authenticator, then enter the 6-digit code.
- The user scans it with Google Authenticator, Microsoft Authenticator, Authy or any TOTP app and enters the code.
- From then on they enter a code after their password on a new browser.
A browser that has passed 2FA is trusted for 30 days, so nobody is prompted on every shift. See First login & 2FA.
Other protections#
| Protection | Detail |
|---|---|
| Strong passwords | At least 12 characters with an uppercase letter, a number and a special character (for sign-up and password resets) |
| Security code at login | A captcha on every sign-in and sign-up attempt |
| Login rate limit | 5 failed attempts per 15 minutes per connection, then Too many requests. Please try again later. |
| Password reset | A 6-digit email code valid for 10 minutes, usable once, cancelled after 5 wrong attempts |
| Sessions | Short-lived access that renews automatically while you work; signing out or being removed ends the session |
| Encrypted secrets | WhatsApp tokens, Razorpay keys, AI calling keys and 2FA secrets are stored AES-256 encrypted |
| Removing a member | Signs them out everywhere immediately |
More in Security & privacy.
Good practice#
- Turn 2FA on for Every user once staff are comfortable with the app.
- Give each person their own login โ never share the Owner's.
- Remove access the day someone leaves.
- Use the lowest access that lets each person do their job; see Module access matrix.
Related#
Last updated 15/09/2026