Promotions

New products

Two-Factor Authentication

c3d20180323183031

This module allows to add a double authentication (Two-Factor) compatible with most unique key generators TOTP (Google Authenticator, Authy, etc ...) and U2F devices (usb key, fingerprints,...) Compatible with the Multicompany module.

140.00 €
Excl. tax

  • Author Régis HOUSSIN (iNodbox)
  • Module version 3.0.0
  • Release date 08/27/2019
  • Access to download and updates 1 year

More info...

Publisher/Licence: Régis Houssin / GPL
User interface language: English, French, Spanish, Italian, German
Help/Support: https://support.inodbox.com / regis.houssin@inodbox.com
Website: https://www.inodbox.com

Upgrades and free support for 1 year then 50% discount on renewals.

TwoFactorAuth adds two-factor authentication (2FA) to Dolibarr: a one-time code (TOTP) from an authenticator app, or a physical/biometric security key (U2F / WebAuthn) - your choice, per user.

Why TwoFactorAuth?

  • A stolen, guessed or reused password is no longer enough to log in: a second factor is required on every login.
  • Choose, per user, between a TOTP code (authenticator app), a physical or biometric security key (Windows Hello, Touch ID, fingerprint reader), or both.
  • One-time recovery codes so you're never locked out if you lose your phone or your security key.

Main features

TOTP (Time-based One-Time Password)

Works with most standard code generators (Google Authenticator, Authy, etc.): enable it by scanning a QR code, generated locally and never sent to a third-party service.

U2F / WebAuthn security keys

Supports physical security keys (USB, NFC, Bluetooth) and platform authenticators (Touch ID, Windows Hello, fingerprint readers), with attestation verification and anti-replay protection.

One-time recovery codes

Ten single-use codes generated in advance from the user card, to log back in if you lose access to both your authenticator app and your security keys at the same time; each code works only once and is never stored or logged in plain text.

LDAP two-factor authentication

A dedicated authentication mode where the first factor (login/password) is verified against an LDAP directory, while the second factor (TOTP, security key or recovery code) is still handled by the module.

Multicompany compatible

Works with the Multicompany module, including per-entity LDAP authentication and switching entity mid-session.

Brute-force protection

Limited, throttled attempts on every verification factor (TOTP code, recovery code), with the same IP-based lockout mechanism as Dolibarr core.

Why choose this module?

  • Developed and maintained by inodbox, a Dolibarr specialist, with regular updates following Dolibarr releases.
  • No modification of the Dolibarr core: clean install and uninstall through the module manager.



If you think this module is a fork of another one (published after the first one) or violates some terms or conditions of use (for users or vendors), you can make a report at dolistore@dolibarr.org