Login Security and OTP Guide¶
This page explains login security options and clarifies the two OTP flows used in KIFWA.
OTP terms (important)¶
KIFWA uses two different OTP concepts:
- Login Email OTP (2FA): one-time code used during account sign-in.
- Operational OTP certificate: workflow artifact used in company customs processing.
Login methods¶
Username/email + password¶
- Enter username or email.
- Enter password.
- Click Continue securely.
Email OTP (if 2FA is enabled)¶
- Enter username/email and password.
- Submit login.
- Check registered email for OTP code.
- Enter code before expiry.
- Complete sign-in.
Passkey sign-in¶
- Click Use passkey on login page.
- Approve native device prompt (Touch ID / PIN / security key).
- Sign-in completes without password.
Passkey prerequisites¶
- Passkey must already be registered in your profile security settings.
- You must sign in on the same effective auth domain where the passkey was registered.
- Browser/device must support WebAuthn.
Login issues and fixes¶
| Issue | What it means | What to do |
|---|---|---|
| No passkey prompt appears | browser did not trigger passkey flow | refresh page, click Use passkey again, confirm browser supports passkeys |
| Prompt says no passkeys available | passkey is not available for this site/device | confirm passkey is registered and use same device/browser profile |
| Email OTP not received | delivery delay or mailbox filtering | check spam/junk, retry login, confirm account email is correct |
| OTP code expired | code timed out | request a new login code and re-enter immediately |
| Account locked/inactive | security or admin restriction | contact portal support/association admin |
Where to manage security settings¶
- Company users: Profile -> Security
- Association users: Profile -> Security
- Customer users: Profile -> Security (if enabled for tenant)
Use those pages to:
- enable/disable Email OTP
- register or remove passkeys
- request password reset email