Skip to main content
SourceTrustSign in

Help center

Guides for SourceTrust: Importing dependencies, reviewing licenses, external obligations, publishing attestation pages, billing, plain-language license explainers, and procurement-oriented explainers for common open-source licenses.

Org-required two-factor authentication

← All articles

Owners can require every member to enroll in 2FA. While that is on, publishing, rolling back, and taking a page offline ask for a fresh authenticator code.

Authenticator sign-in and identity confirmations limit repeated code attempts and new code requests. A wrong code keeps the same confirmation active. Follow any displayed wait time before trying again. A confirmation lasts at most five minutes: use Start again after expiry, or Send a new code for email. If authenticator sign-in expires, go back and sign in again. Reopening the dialog or choosing another project does not remove the wait.

Deleting a project, organization, or your own account always asks you to confirm your identity. If you have an authenticator enrolled, use its code. Otherwise the dialog sends a code to your account email as it opens. Email fallback is for deletion; policy changes and required publish, unpublish, and rollback confirmations still need an authenticator. Account deletion also requires you to resolve any sole-owner blockers first.

Two-factor authentication (2FA) is optional for each person by default (Profile > Security). An organization owner can require it for the whole org. While that policy is on, publishing a page, rolling back to a previous revision, and taking a published page offline also ask for a fresh authenticator code.

Requiring 2FA for every member

  • Only the owner can turn this on, from Organization settings (or when creating the organization), and only after entering a fresh authenticator code themselves when changing it in settings. Creating an org with the requirement on does not ask for a code; if you do not have 2FA yet, you will set it up right after create. The owner must already have 2FA enrolled before they can require it for others from Settings.
  • Once on, a member without 2FA is sent straight to the enrollment screen on their next sign-in to that org. There is no "Skip for now": they must set up an authenticator app before continuing.
  • This applies to new invitations, first login, and existing members' next session into that org.
  • While you belong to an org that requires 2FA, you cannot turn it off for your account, even from a different org's settings. You would need to leave that org, or ask its owner to turn the policy off.
  • One authenticator app covers every organization you belong to. If you already have 2FA on, joining or being required to join a stricter org changes nothing for you.

Publishing, rollback, and taking a page offline

  • When org-required 2FA is on, Publish, Roll back to here, and Take page offline ask for a fresh 6-digit authenticator code, then Confirm (the code does not auto-submit). For Publish and Rollback that comes before the last-chance countdown. There is no separate toggle for that.
  • Publish when merged (auto-publish after a GitHub/GitLab/Azure DevOps merge) never asks for a code.
The member-2FA toggle is owner-only, the same protection level as your organization's publishing policy and organization deletion.