Sign in and manage MFA
Sign in with a local or linked OIDC identity and manage TOTP, passkeys, recovery codes, sessions, and CLI tokens.
Tenvyr supports invitation-only local accounts and optional OIDC sign-in through Microsoft Entra ID, Okta, Google, or a compatible provider. Every method is followed by Tenvyr’s built-in MFA.
Sign in
- Open
https://app.tenvyr.com/login. - Enter your organization or tenant login handle.
- Choose local password or a configured identity provider.
- Complete Tenvyr MFA.
Tenvyr does not link identities by email or UPN. A provider identity must be explicitly linked or provisioned through an exact immutable SCIM external ID.
Add a security key or passkey
Open Security, enter a recognizable display name, and choose Register security key or passkey. The browser requires user verification during the WebAuthn ceremony.
Use at least two independent authenticators for privileged accounts. A roaming hardware security key provides a recovery path if the platform passkey becomes unavailable.
Rotate the authenticator app
In Security:
- Enter a label for the replacement TOTP authenticator.
- Start rotation.
- Add the new secret to the intended authenticator.
- Enter its current six-digit code.
The existing authenticator remains active until the replacement is proven. Successful rotation signs the account out everywhere and revokes CLI tokens.
Recovery codes
Recovery codes are one-use account credentials. Store them offline. Rotating codes invalidates the previous set and signs the account out across every tenant.
Tenvyr never displays stored recovery codes again.
Sessions and tokens
The Security page lists browser sessions and CLI/API tokens for the global account. Revoking one entry requires recent MFA. Password changes, factor rotation, and some identity-link changes revoke broader account state automatically.
Password recovery
Use Forgot password on the login page. The response is deliberately the same whether or not the email exists. A recovery link is single-use, expires after 15 minutes, and revokes sessions and tokens after completion while preserving existing MFA factors.