Sign-in

Require members to sign in with a second factor, choose which ones count, and see who has one.

Updated Oct 11, 2026

The Sign-in section under Settings decides whether members must sign in with a second factor to enter your Burrow, and which second factors count. RatelKey holds the rule and checks it on every request, so it applies to everyone signed in, from their next click.

Viewing the section needs permission to read Sign-in, which also shows which second factors each member has on the Members page. Changing the rule needs permission to change it. The owner has both; no built-in role includes them, and a custom role can grant them.

Requiring a second factor#

Turn on Require a second factor to sign in. The accepted factors below it stay greyed out until the switch is on. Then choose which second factors count; nothing is chosen until you choose:

  • Any 2FA. Every second factor a member can have: an authenticator app or any passkey, and any kind of second factor added later.

  • Specific factors. Tick the ones that count. Authenticator app: a code from an app such as 1Password, Authy or Google Authenticator. Passkey, and which: Any passkey; Device-bound only, a passkey that never leaves the device it was made on, so not one synced through iCloud Keychain or Google Password Manager; or Security key only, a removable key whose model RatelKey has verified.

Only one of the two can be chosen, and selecting the chosen one again clears it. Save stays disabled until something counts. Your Factors shows the second factors your own account has.

Turning the rule off keeps your choices, greyed out, for when it's turned on again.

What counts#

The rule looks at how each session was signed in, not only at what the account has. A session counts when its sign-in used an accepted factor and the account still has that factor:

  • A password or GitHub followed by an accepted factor counts. A password or GitHub on its own doesn't.

  • Signing in with a passkey alone counts, at that passkey's type.

  • A recovery code typed in place of an authenticator code counts as the authenticator app, while the app is still on the account. Recovering an account with a recovery code doesn't count.

  • A factor confirmed afterwards, in the RatelKey window that saving the rule opens or on the sign-in page, counts the same as one used to sign in.

  • Removing the factor a session signed in with ends that session's access on its next request, even if the account has another.

Removing a second factor while signed in#

A member can turn off their authenticator app or remove a passkey at any time, from Account in the Burrow or from their RatelKey account. If their session was signed in with that factor, and proved no other factor the rule accepts, their access ends on their next request: the Burrow signs them out and asks them to sign in again. Removing a factor their session didn't use changes nothing for it.

Every other session they have in the Burrow that was signed in with that factor ends the same way, each on its next request.

Signing back in, RatelKey's sign-in page asks for another factor the rule accepts if they still have one, and they carry on into the Burrow. With none left, they can't enter until they set one up.

The owner can't remove a factor the rule holds them to; see The owner below.

Turning it on#

Requiring a factor is refused until you have an accepted factor, and until the Burrow's owner has one too. The message names what's missing, such as "You need to set up 2FA before you can enable this feature." Set up an authenticator app under Account in the Burrow or on your RatelKey account, and a passkey on your RatelKey account.

If you have an accepted factor but didn't sign in with it this time, Save opens a RatelKey window that asks for it: a code from your authenticator app, or your passkey. Confirm it there and the save carries on, and from then on your session counts as signed in with it.

Before the rule is saved, the section shows what it will do: how many sessions it signs out, and which members have no accepted factor yet. Confirm with Require it. Every session in the Burrow that doesn't meet the rule is signed out at once, the owner's other sessions included. Members without an accepted factor can't enter until they set one up.

Changing the accepted factors while the rule is on works the same way. Turning the rule off signs nobody out.

When a member is refused#

A member whose sign-in doesn't meet the rule is told so on RatelKey's sign-in page. If their account has an accepted factor, the page asks for it there, and once it's confirmed the same sign-in carries on into the Burrow. If it has none, they set one up on their RatelKey account and sign in again.

The owner#

The rule holds the owner like everyone else. While it needs a factor, the owner can't turn off their authenticator app or remove a passkey if that would leave them without an accepted factor, from the Burrow or from their RatelKey account. Turn the rule off first.

With single sign-on#

While the Burrow's single sign-on is on, members are signed in by your identity provider, which decides their second factor, and the rule applies to the owner alone. A session that came through the identity provider is never held to it.

Members' second factors#

With permission to read Sign-in, the Members page shows each member with a 2FA tag, listing their factors when you point at it, or No 2FA.

In the audit log#

Opening the section is recorded as sign-in.view, and saving the rule as sign-in.change, with the accepted factors and how many sessions it signed out. Webhooks can send both as they happen.