Skip to main content

Multi-Factor Authentication (MFA / 2FA)

Okustera supports Time-based One-Time Password (TOTP) Multi-Factor Authentication (MFA / 2FA) to secure customer accounts and satisfy ISO/IEC 27001 (Control A.8.2) access control requirements.

Once enabled, logging into the Okustera Cloud Portal or requesting session tokens requires both your account password and a rolling 6-digit verification code generated by an authenticator application (such as Google Authenticator, 1Password, or Bitwarden).


Setting up 2FA in the Cloud Portal​

Step-by-Step Activation Guide​

  1. Log into the Okustera Cloud Portal.
  2. Click your profile icon in the upper right navigation bar and select Settings (/settings).
  3. Under the Two-Factor Authentication (2FA) section, click Enable Two-Factor Authentication.
  4. A secure setup modal will display:
    • QR Code: Scan this code with your mobile authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Authy).
    • Manual Entry Key: If your device camera is unavailable, copy the alphanumeric setup secret into your authenticator app.
  5. In the Verification Code input field, enter the current 6-digit code displayed in your authenticator app.
  6. Click Verify and Activate.
  7. Once activated, your profile status will update to 2FA Protected. All subsequent logins will prompt for a 6-digit code upon entering your password.

Disabling 2FA​

To disable two-factor authentication:

  1. In the Settings page (/settings), click Disable 2FA.
  2. For security validation, enter a current 6-digit code from your authenticator app.
  3. Confirm the action to deactivate 2FA.

Authenticating with 2FA via API & CLI​

When 2FA is active on an account, programmatic API logins and Terraform authentication require passing the current 6-digit TOTP code alongside your credentials.

API Login (POST /api/v1/auth/login)​

curl -X POST https://portal.okustera.com/api/v1/auth/login \
-H "Content-Type: application/json" \
-d '{
"username": "<YOUR_USERNAME>",
"password": "<YOUR_PASSWORD>",
"totp_code": "<6_DIGIT_TOTP_CODE>"
}'

The endpoint validates both factors and returns a signed JWT access token.

Terraform Provider Authentication​

You can pass your TOTP verification code to the Okustera Terraform provider via variables or environment variables:

provider "okustera" {
api_endpoint = "https://portal.okustera.com/api/v1"
username = var.okustera_username
password = var.okustera_password
totp_code = var.okustera_totp_code # Required when 2FA is enabled
tenant_id = var.okustera_tenant_id
}

Or configure via environment variables:

export OKUSTERA_USERNAME="<YOUR_USERNAME>"
export OKUSTERA_PASSWORD="<YOUR_PASSWORD>"
export OKUSTERA_TOTP_CODE="123456"
export OKUSTERA_TENANT_ID="tenant-production"

terraform apply
Personal Access Tokens for CI/CD

For automated CI/CD pipelines (GitLab CI, GitHub Actions), do not use user credentials with dynamic 2FA codes. Instead, use a scoped Personal Access Token (PAT) or Kubernetes Workload Identity, which bypass interactive 2FA checks while maintaining least-privilege scoping.


REST API Reference​

  • POST /api/v1/auth/2fa/setup — Generate a new TOTP secret key and QR code provisioning URI.
  • POST /api/v1/auth/2fa/activate — Submit initial 6-digit verification code to activate 2FA on user account.
  • POST /api/v1/auth/2fa/verify — Validate a 6-digit code during authentication challenge.
  • POST /api/v1/auth/2fa/disable — Provide a valid 6-digit code to deactivate 2FA.