Diska
Settings

Two-factor authentication

Where two-factor authentication stands in Diska.
Not available yet. The Two-factor authentication card under Settings → Credentials reads "Coming soon" and has no enable button. This page describes what is planned, not what you can do today.

TOTP enrolment did exist in the product and was deliberately withdrawn: nothing in the sign-in flow verified the second factor, and recovery codes had no way to be redeemed. A card claiming "Enabled" for a protection that protected nothing is worse than offering no 2FA at all — so it stays hidden until sign-in genuinely requires the challenge.

In the meantime

Your account is still protected by:

  • a password with strength rules, changeable in Settings → Credentials;
  • Google sign-in, where your organisation uses it;
  • active sessions you can revoke at any time in Settings → Sessions;
  • security activity, which records sign-ins and sensitive changes.

What is missing before it can be enabled

  1. Sign-in must require the TOTP challenge (assurance level aal2).
  2. Recovery codes need a redemption path — without one, ten strings look like a way back in and are not.

Once both exist, the card stops saying "Coming soon" and this page will describe enabling, recovery codes and disabling.

SMS 2FA, passkeys and enterprise SSO are not planned for the MVP.

Copyright © 2026