Security

Security

MFA, passkeys, PKCE, audit logging, and operator policies for internal Capnis SSO.

MFA & passkeys

Configurable requirements for customers, employees, and admins—TOTP 2FA or WebAuthn passkeys before sensitive SSO flows.

PKCE required

Per-site enforcement of Proof Key for Code Exchange protects public Capnis website clients from authorization code interception.

IP allowlists

Restrict OAuth authorization and token endpoints to known IP ranges for high-trust Capnis website integrations.

Registration approval

Optional operator approval before new customer accounts can sign in to Capnis websites.

Verified email gate

SSO flows can require verified email addresses before granting tokens to a Capnis website.

Audit logging

Structured SSO audit events: sign-in, role sync, provisioning, new IP detection, and webhook delivery.

Security headers

Global security headers middleware on all web responses from the authorization server.

Session control

Users revoke sessions or sign out everywhere; admins can force-logout and revoke tokens per Capnis website.

Capnis operators rotate Passport keys, revoke compromised OAuth sites, and monitor webhook delivery from the admin console. High-risk scopes can trigger additional MFA before a Capnis website receives tokens.

See the Developers page for token validation guidance and Contact to report security issues affecting Capnis SSO.

Passkeys & MFA in the user portal

Signed-in users enable TOTP or WebAuthn passkeys under Profile → Security before accessing connected Capnis websites.