GitDBDocs
gitdb.co platform

Security and 2FA

Protect your gitdb.co sign-in with emailed one-time codes, understand how GitHub and Google sign-ins and organization requirements interact with it, and sign in with enterprise SSO.

Two-step sign-in with an emailed code

gitdb.co can add a second step to email-and-password sign-in: after your password, you enter a one-time code that gitdb.co emails you.

To turn it on:

  1. Open Settings and choose Password & 2FA. The page is titled Two-factor authentication.
  2. Next to Email one-time code (Status: Off), click Turn on.

The status changes to On. Click Turn off to switch it off again.

"If you sign in with Google or GitHub, that provider’s own 2FA already applies and this setting has no additional effect." Turn on two-factor authentication at your Google or GitHub account to protect those sign-ins.

Signing in with a code

When a code is required, signing in with your email and password takes one more step:

  1. After SIGN IN →, the page says "Enter the 6-digit code we emailed you to finish signing in."
  2. Enter the code from the email in Email code and click VERIFY →.
  3. If the email doesn't arrive, click Resend code. The page confirms "A new code has been sent."

You're signed in only after the code is accepted.

When your organization or enterprise requires it

Your sign-in can require an emailed code even if you haven't turned it on yourself:

  • Organization: an organization owner can turn on Require two-factor authentication in the organization's Enterprise settings: "Every member who signs in with email + password must enter an emailed one-time code. Members who use Google/GitHub already get their provider's 2FA. Available on all plans."
  • Enterprise: an enterprise owner can enforce the Require 2FA policy for every organization in the enterprise.

Sign in with enterprise SSO

If your company has set up single sign-on for its enterprise:

  1. On gitdb.co/login, find Enterprise single sign-on at the bottom.
  2. Enter your work email (you@company.com) and click SIGN IN WITH SSO →.
  3. You're sent to your company's identity provider to sign in, then back to gitdb.co.

gitdb.co finds your company's SSO from your email's domain. If there isn't one, you'll see "No SSO is configured for this email domain. Use your password or a provider above." Administrators set SSO up in the enterprise console.

Keep your access secure

  • Give each personal access token only the scopes it needs and an expiry date, and revoke tokens you no longer use.
  • Delete SSH keys for computers you no longer use. Each key shows when it was last used.
  • Never paste a private key or a token into a chat or commit it to a repository.

On this page