1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Unmaintained [FreddysHouse] Two-factor Authentication 1.3.3

Add two-factor authentication to your community.

  1. SheepCow
    Compatible XF Versions:
    • 1.2
    • 1.3
    Creative Commons Attribution 3.0 Unported (CC BY 3.0), GNU General Public License and MIT license
    Visible Branding:
    Add-on is now managed by @Deebs

    This add-on provides XenForo with two-factor authentication using Google's Authenticator app or Yubico YubiKeys.

    The idea behind multi-factor authentication is that you don't rely on just a password to login - instead you require (at least) two of these:
    • Something the user knows (their password).
    • Something the user has (a YubiKey, the Google Authenticator app on their smartphone).
    • Something the user is (a fingerprint, not used in this add-on).
    If a hacker is able to gain access to the user's password (e.g. a bad person installs a key logger on the user's computer) they are still not able to log in without physical access to the two-factor device.

    I recommend also installing [FreddysHouse] Logger, this add-on will log useful information only if that add-on is installed.

    The add-on has the following features:
    • Supports Google Authenticator time-based keys.
    • Supports Yubico YubiKeys.
    • Controlled by permissions.
    • Trophy criteria for users that are using two-factor authentication.
    • Provides detailed logging for admins (if [FreddysHouse] Logger is installed).
    • Provides additional security for your community & also protects your admin control panel.
    • Supports lost keys (works in the same way as a lost password, emails the user for validation and disables two-factor authentication for the user if they click a link in the email).

    Upload the contents of the upload directory to your XenForo directory. Install the add-on XML using the control panel.

    Once installed, go to the 'Home' tab, then click 'Install Method' from the 'Two-factor Authentication' section of the menu (if you cannot see the 'Two-factor Authentication' section please give yourself the 'Manage two-factor authentication' admin permission).

    Select the XML file of the method you wish to install (e.g. twofactor-GoogleAuthenticator.xml for Google Authenticator). You can repeat this to install different methods.

    Once you've added a method you should then configure the permissions. There are two permissions you can configure:

    • Use two-factor authentication. This lets you control which users are able to use two-factor authentication.
    • Maximum two-factor keys. Configure how many keys a user can have.
    Yubico Yubikey authentication requires an API key in order to communicate with the Yubico authentication servers. You can get an API key from them here(you need to own a YubiKey to generate an API key).


    A special two-factor section has been added to the 'Your Account' section of XenForo. From here users can view, add and remove two-factor authentication keys.

    This add-on uses jQuery.qrcode by Lars Jung.

    Funded by and developed for FreddysHouse (http://www.freddyshouse.com).
    Related Resources:
    This add-on uses [FreddysHouse] Logger for logging.


    1. account_twofactor_2.png
    2. account_twofactor.png
    3. add_google_authenticator.png
    4. add_yubico_yubikey.png
    5. admin_login_twofactor.png
    6. admin_login.png
    7. admin_twofactor_list.png
    8. admin_twofactor_yubico_yubikey_options.png
    9. bad_twofactor_code.png
    10. entering_twofactor_code.png
    11. twofactor_login_2.png
    12. user_menu.png
    SchmitzIT, t0fx, lasertits and 6 others like this.

Recent Reviews

  1. TDUBS
    Version: 1.3.3
    Awesome addon. My users like the assurance that their account is secure from malicious attackers. Thank you for the work and I also thank you for the logger which I use as well.
  2. Shiro
    Version: 1.3.3
    This is a good implementation of 2FA. The only issues I have with are that (a) social logins are not verified and (b) you can turn off two factor authentication when logged in to your account without verifying your token or sending a verification email. I feel this defeats the purpose of the additional check on the AdminCP. I will adjust to five stars once this is fixed.
  3. Maxxamillion
    Version: 1.3.3
    This is awesome the google auth is brilliant
  4. pipibunny
    Version: 1.3.2
    Awesome. It's great to security for account
  5. Tracy Perry
    Tracy Perry
    Version: 1.3.2
    Want security? Then this is the add-on for you. Works for both the ACP and site itself.
  6. Shiro
    Version: 1.3.1
    Great additional layer of security. Would rate five stars if you could require two-factor authentication even if Facebook login is enabled.
  7. MattW
    Version: 1.3.0
    Great add-on for that extra layer of security
  8. sonnb
    Version: 1.2.8
  9. Andy.N
    Version: 1.1.2
    Great addon and it just works as it should. Highly recommended for admin of all sites.
  10. Mouth
    Version: 1.1.2