Signing in and two-factor authentication
A password needs at least 8 characters with upper and lower case, a digit and a special character; a session lasts 24 hours from its last use; a reset link lasts three hours; ten failed attempts lock sign-in for up to 15 minutes. Two-factor authentication is a six-digit code from any authenticator app.
Passwords and reset links#
A special character is anything other than an unaccented letter, a digit or an underscore. A reset link is valid for three hours and requesting another cancels the first; the reset page answers the same way whether or not the address is a user. Setting a new password signs out every session you had. Changing your own password from Account then Settings goes through the same flow.
Lockouts#
Ten failed attempts within 15 minutes lock sign-in until fewer than ten fall inside the last 15 minutes, counted for the email address and for the address you connect from. A successful sign-in clears the count for that email address. Two-factor codes have a count of their own, and so do password reset requests, where every request counts, failed or not, and a locked address is told a link was sent while none is.
Sessions#
A session ends 24 hours after its last use, and each request moves that forward. What ends one early: signing out; a password reset, which ends every session; switching two-factor authentication on or off, which ends your other sessions; a change to your permission level; changing your email address, which ends the session you did it from and stops the others until the new address is verified; revoking the session from the Users page; being removed from the account; and the account being suspended, which signs every user out.
Changing your email address#
Changing the address on your profile signs you out and sends a verification link to the new address, valid for 72 hours. Until you open it you cannot sign in, so make sure the new mailbox is one you can read before you save. If the link runs out, ask our team to send it again.
Two-factor authentication#
Under Account then Settings, in Security Settings, switch 2-Factor Authentication on and scan the QR code, or type the setup key, into any app that produces time-based codes. The page makes a new key each time it is opened, so add it to the app and enter the code in the same visit. A refused code keeps that key: enter the code the app shows now, with no need to scan again. Enabling it signs out your other sessions. Switching it off turns it off at once, with no code asked for, and signs out your other sessions; on an account that enforces two-factor authentication, switching it off sends you straight back to the setup page.
A Full Access user can switch on Enforce 2FA for All Users. From then on any user on the account who has not set it up is taken to the setup page on their next request, signed in already or not, and cannot go anywhere else until it is done.
If you lose your authenticator, email team@cachegenie.com from the address you sign in with and quote the account's support PIN, which another user on the account can read from the Support page. Our team switches two-factor authentication off, signs you out everywhere and emails you; sign in with your password and set it up again.