Multi-Factor Authentication (MFA / 2FA)
Okustera supports Time-based One-Time Password (TOTP) Multi-Factor Authentication (MFA / 2FA) to secure customer accounts and satisfy ISO/IEC 27001 (Control A.8.2) access control requirements.
Once enabled, logging into the Okustera Cloud Portal or requesting session tokens requires both your account password and a rolling 6-digit verification code generated by an authenticator application (such as Google Authenticator, 1Password, or Bitwarden).
Setting up 2FA in the Cloud Portal
Step-by-Step Activation Guide
- Log into the Okustera Cloud Portal.
- Click your profile icon in the upper right navigation bar and select Settings (
/settings). - Under the Two-Factor Authentication (2FA) section, click Enable Two-Factor Authentication.
- A secure setup modal will display:
- QR Code: Scan this code with your mobile authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Authy).
- Manual Entry Key: If your device camera is unavailable, copy the alphanumeric setup secret into your authenticator app.
- In the Verification Code input field, enter the current 6-digit code displayed in your authenticator app.
- Click Verify and Activate.
- Once activated, your profile status will update to 2FA Protected. All subsequent logins will prompt for a 6-digit code upon entering your password.
Disabling 2FA
To disable two-factor authentication:
- In the Settings page (
/settings), click Disable 2FA. - For security validation, enter a current 6-digit code from your authenticator app.
- Confirm the action to deactivate 2FA.
Authenticating with 2FA via API & CLI
When 2FA is active on an account, programmatic API logins and Terraform authentication require passing the current 6-digit TOTP code alongside your credentials.
API Login (POST /api/v1/auth/login)
curl -X POST https://portal.okustera.com/api/v1/auth/login \
-H "Content-Type: application/json" \
-d '{
"username": "<YOUR_USERNAME>",
"password": "<YOUR_PASSWORD>",
"totp_code": "<6_DIGIT_TOTP_CODE>"
}'
The endpoint validates both factors and returns a signed JWT access token.
Terraform Provider Authentication
You can pass your TOTP verification code to the Okustera Terraform provider via variables or environment variables:
provider "okustera" {
api_endpoint = "https://portal.okustera.com/api/v1"
username = var.okustera_username
password = var.okustera_password
totp_code = var.okustera_totp_code # Required when 2FA is enabled
tenant_id = var.okustera_tenant_id
}
Or configure via environment variables:
export OKUSTERA_USERNAME="<YOUR_USERNAME>"
export OKUSTERA_PASSWORD="<YOUR_PASSWORD>"
export OKUSTERA_TOTP_CODE="123456"
export OKUSTERA_TENANT_ID="tenant-production"
terraform apply
For automated CI/CD pipelines (GitLab CI, GitHub Actions), do not use user credentials with dynamic 2FA codes. Instead, use a scoped Personal Access Token (PAT) or Kubernetes Workload Identity, which bypass interactive 2FA checks while maintaining least-privilege scoping.
REST API Reference
POST /api/v1/auth/2fa/setup— Generate a new TOTP secret key and QR code provisioning URI.POST /api/v1/auth/2fa/activate— Submit initial 6-digit verification code to activate 2FA on user account.POST /api/v1/auth/2fa/verify— Validate a 6-digit code during authentication challenge.POST /api/v1/auth/2fa/disable— Provide a valid 6-digit code to deactivate 2FA.