Authentication
Penvio supports multiple authentication methods to keep your account secure.
Email & Password
The default authentication method. Use a strong, unique password and consider enabling two-factor authentication.
Password Requirements
- Minimum 8 characters
- At least one uppercase letter
- At least one lowercase letter
- At least one number
- At least one special character recommended
Changing Your Password
- Go to Settings → Security
- Click Change Password
- Enter your current password
- Enter and confirm your new password
- Click Update Password
Google OAuth
Sign in with your Google account:
- Click “Sign in with Google” on the login page
- Select your Google account
- Grant Penvio the required permissions
Google OAuth users can still enable two-factor authentication for additional security.
SAML SSO (Enterprise)
Business and Enterprise plans support SAML 2.0 single sign-on:
- Integrate with your identity provider (Okta, Azure AD, OneLogin, etc.)
- Centralized user management
- Automatic provisioning with SCIM
See SAML SSO Configuration for setup instructions.
Two-Factor Authentication (2FA)
Add an extra layer of security with time-based one-time passwords (TOTP).
How It Works
When 2FA is enabled:
- Enter your email and password as usual
- Open your authenticator app
- Enter the 6-digit code displayed
- Access granted
Supported Authenticator Apps
Any TOTP-compatible app works:
- Google Authenticator
- Microsoft Authenticator
- Authy
- 1Password
- Bitwarden
- And many others
Setting Up 2FA
Open Security Settings
Go to Settings → Security
Start Setup
Click Enable Two-Factor Authentication
Scan QR Code
Open your authenticator app and scan the QR code displayed
If you can’t scan, click Enter code manually to type the secret key
Verify Setup
Enter the 6-digit code from your authenticator app to confirm setup
Save Backup Codes
Important: Save your backup codes in a secure location. You’ll need them if you lose access to your authenticator app.
Store your backup codes securely. They are the only way to access your account if you lose your authenticator device.
Backup Codes
When you enable 2FA, you receive 10 backup codes:
- Each code can only be used once
- Use them if you can’t access your authenticator
- Generate new codes anytime (invalidates old ones)
To generate new backup codes:
- Go to Settings → Security
- Click Regenerate Backup Codes
- Save the new codes securely
Signing In with 2FA
After entering your password:
- Open your authenticator app
- Find the Penvio entry
- Enter the current 6-digit code
- Code changes every 30 seconds
Using a backup code:
- Click Use a backup code
- Enter one of your saved backup codes
- That code is now used and cannot be reused
Disabling 2FA
Disabling 2FA reduces your account security. Only disable if necessary.
- Go to Settings → Security
- Click Disable Two-Factor Authentication
- Enter a verification code from your authenticator
- Confirm disabling
Lost Access to Authenticator
If you lose your authenticator device:
- Use a backup code to sign in
- Go to Settings → Security
- Disable and re-enable 2FA with your new device
If you don’t have backup codes, contact support for account recovery verification.
Session Management
View and manage your active sessions:
Viewing Sessions
- Go to Settings → Security
- Scroll to Active Sessions
- See all devices where you’re signed in
Session information includes:
- Device type and browser
- Location (approximate, based on IP)
- Last activity time
- Current session indicator
Revoking Sessions
To sign out a specific device:
- Find the session in the list
- Click Revoke
- That device is immediately signed out
Sign Out Everywhere
To sign out all devices except your current one:
- Go to Settings → Security
- Click Sign Out All Other Sessions
- Confirm the action
Use this if you suspect unauthorized access or after changing your password.
Security Best Practices
| Practice | Why It Matters |
|---|---|
| Enable 2FA | Prevents unauthorized access even if password is compromised |
| Use unique password | Prevents credential stuffing attacks |
| Review sessions regularly | Detect unauthorized access early |
| Save backup codes securely | Ensures account recovery is possible |
| Sign out on shared devices | Prevents unauthorized access |
Next Steps
- Account Setup - Configure your profile settings
- Organizations - Set up your team workspace
- SAML SSO Configuration - Configure enterprise single sign-on