Skip to content
Kapda StockDocs

Security & two-factor auth

Turn on two-factor authentication for the owner or every user, how trusted browsers work, what staff see on their next login, and the other account protections Kapda Stock applies.

Two-factor authentication (2FA) asks for a six-digit code from an authenticator app in addition to the password, so a stolen password alone cannot open your business.

Turn on 2FA#

Owner or Admin:

  1. Open Settings โ†’ ๐Ÿ” Security โ€” Two-factor authentication โ€” Require a one-time code from an authenticator app at login. Off by default.
  2. Choose On โ€” An authenticator app is set up, and a 6-digit code is needed when signing in on a new device. You see Two-factor authentication enabled.
  3. Under Who does it apply to? choose:
    • Owner only โ€” Just your own account. Staff sign in with a password.
    • Every user โ€” Admins, managers and cashiers too โ€” any of those accounts can reach your data. Each sets up an app on their next login.

Choosing Off โ€” Logging in needs only an email & password โ€” turns it off for everyone.

The owner is always covered while 2FA is on, whichever scope is chosen.

What happens at the next login#

For each covered account:

  1. After the password, the login page shows a QR code: Two-factor authentication keeps your business safe. Scan with Google Authenticator, then enter the 6-digit code.
  2. The user scans it with Google Authenticator, Microsoft Authenticator, Authy or any TOTP app and enters the code.
  3. From then on they enter a code after their password on a new browser.

A browser that has passed 2FA is trusted for 30 days, so nobody is prompted on every shift. See First login & 2FA.

Other protections#

ProtectionDetail
Strong passwordsAt least 12 characters with an uppercase letter, a number and a special character (for sign-up and password resets)
Security code at loginA captcha on every sign-in and sign-up attempt
Login rate limit5 failed attempts per 15 minutes per connection, then Too many requests. Please try again later.
Password resetA 6-digit email code valid for 10 minutes, usable once, cancelled after 5 wrong attempts
SessionsShort-lived access that renews automatically while you work; signing out or being removed ends the session
Encrypted secretsWhatsApp tokens, Razorpay keys, AI calling keys and 2FA secrets are stored AES-256 encrypted
Removing a memberSigns them out everywhere immediately

More in Security & privacy.

Good practice#

  • Turn 2FA on for Every user once staff are comfortable with the app.
  • Give each person their own login โ€” never share the Owner's.
  • Remove access the day someone leaves.
  • Use the lowest access that lets each person do their job; see Module access matrix.

Last updated 15/09/2026