TVTenvyrDocs
User guide

Sign in and manage MFA

Sign in with a local or linked OIDC identity and manage TOTP, passkeys, recovery codes, sessions, and CLI tokens.

Tenvyr supports invitation-only local accounts and optional OIDC sign-in through Microsoft Entra ID, Okta, Google, or a compatible provider. Every method is followed by Tenvyr’s built-in MFA.

Sign in

  1. Open https://app.tenvyr.com/login.
  2. Enter your organization or tenant login handle.
  3. Choose local password or a configured identity provider.
  4. Complete Tenvyr MFA.

Tenvyr does not link identities by email or UPN. A provider identity must be explicitly linked or provisioned through an exact immutable SCIM external ID.

Add a security key or passkey

Open Security, enter a recognizable display name, and choose Register security key or passkey. The browser requires user verification during the WebAuthn ceremony.

Use at least two independent authenticators for privileged accounts. A roaming hardware security key provides a recovery path if the platform passkey becomes unavailable.

Rotate the authenticator app

In Security:

  1. Enter a label for the replacement TOTP authenticator.
  2. Start rotation.
  3. Add the new secret to the intended authenticator.
  4. Enter its current six-digit code.

The existing authenticator remains active until the replacement is proven. Successful rotation signs the account out everywhere and revokes CLI tokens.

Recovery codes

Recovery codes are one-use account credentials. Store them offline. Rotating codes invalidates the previous set and signs the account out across every tenant.

Tenvyr never displays stored recovery codes again.

Sessions and tokens

The Security page lists browser sessions and CLI/API tokens for the global account. Revoking one entry requires recent MFA. Password changes, factor rotation, and some identity-link changes revoke broader account state automatically.

Password recovery

Use Forgot password on the login page. The response is deliberately the same whether or not the email exists. A recovery link is single-use, expires after 15 minutes, and revokes sessions and tokens after completion while preserving existing MFA factors.

On this page