Login & Account Security
Complete sign-up, email verification, password recovery, TOTP, and SSO login
Clouisle's authentication flow may include password, email verification, administrator approval, CAPTCHA, password changes, TOTP, and SSO. Site settings determine which steps are enabled.
Sign-up & Email Verification
- Select Sign up and fill in the username, email, password, and confirm password.
- The password must be at least
8characters; administrators can raise the minimum length and require uppercase letters, numbers, or special characters. - If the site requires it, check the user agreement and privacy policy.
- After submitting, verify your email with the verification code or link in the email.
- If administrator approval is enabled, the account enters a pending-approval state and cannot log in until approved.

Login Protection
Login may require a click-through CAPTCHA. The CAPTCHA proof is valid for 300 seconds (5 minutes) by default; re-fetch it after a failure or expiration. Repeated failures trigger account lockout and rate limiting.
Password Recovery & Expiration
Send a reset email from Forgot password, enter the verification code, and set a new password. Administrators can configure password history, minimum change interval, expiration period, and forced change on first login. When a password expires or is force-changed, you must complete Change password first.
TOTP Two-Factor Authentication
- Open Two-factor authentication in account settings, or follow the administrator-enforced wizard.
- Scan the QR code with an authenticator app, or enter the secret manually.
- Enter the 6-digit verification code to confirm.
- Download or copy the one-time backup codes; each backup code can only be used once.
- Enter TOTP on subsequent logins; use a backup code when your device is unavailable.

SSO Login
After SSO is enabled, the login page shows the providers configured by the administrator. If password login is also disabled, the username/password form is unavailable. SSO settings determine whether the first SSO login auto-creates users, whether approval is required, and whether existing accounts are matched by email.
Related pages: SSO configuration, Site security reference.
How is this guide?