KakapoWPKakapoWP
Log inTry for free
Help Center/Security/Enable two-factor by email

Enable two-factor by email

Applies to: Kakapo Security·3 min read

With two-factor sign-in active, after the correct password the sign-in asks for an additional code, which the plugin sends to the email address stored in the account. The procedure works with email only — TOTP or an authenticator app are not provided for. It is switched on in two stages: once globally and then for each account individually.

Setting up

  1. Call up “Kakapo Security” and click “Two-factor” (in German: „Zwei-Faktor“) in the left sidebar.
  2. In the “Two-factor protection” card, flip the “2FA active globally” switch. Out of the box it is off.
  3. The “Email sending (wp_mail)” row in the same card merely reports whether the mail function of WordPress is present — whether a message is actually delivered is not something the plugin checks.
  4. Scroll to the “Administrators” card and enable the prompt for the accounts you want using the “Activate” button.
  5. Try the procedure out in a private window or in a second browser before you sign out of your current session.

What happens when you sign in

  • After the correct password, the “Confirmation required” screen appears with the “Confirmation code” field and the “Confirm sign-in” button.
  • The code has six digits and is valid for ten minutes.
  • The subject line of the email contains the host name of the site and the code.
  • If sending reports an error, a corresponding note appears on the confirmation screen.
  • Five wrong entries are allowed; after that the process is discarded and the sign-in starts again from the beginning.
  • Sign-ins via REST or with application passwords do not go through the prompt.
The “Administrators” card lists accounts with the Administrator role sorted by user name and shows at most 100 entries; accounts with other roles cannot be switched here. The same button switches the prompt off again for an account.
Was this article helpful?