Two-Factor Authentication

Secure your logins with one-time codes! Learn how to generate secrets, enable/disable 2FA.

Two-factor authentication (2FA) in Directus is a security measure that requires a generated one-use code to be provided after log in to complete authentication. Users can enable 2FA from their user page. A one-time password (OTP) is required when logging in via the Data Studio or API.

To require 2FA, enable Require 2FA on a policy. Directus enforces 2FA if at least one of the user's policies has it enabled. A policy with an IP allowlist only requires 2FA when the user logs in from an allowed IP address. Users who have not set up 2FA are redirected to set it up after logging in, including after SSO logins.

To enable 2FA, you will need an external authenticator app or support for OTPs in your password manager.

Generate 2FA Secret

A 2FA secret is required to set up OTPs in your authenticator app.

POST /users/me/tfa/generate
{
    "password": "d1r3ctu5"
}

The response will contain the secret and an otpauth_url which can be optionally rendered as a QR code and to be used by authenticator apps.

Save the secret in your authenticator app either manually or via the otpauth_url QR code.

Enable 2FA

To complete 2FA setup, you will need both the secret and a generated otp from your authenticator app.

POST /users/me/tfa/enable
{
    "otp": "123456",
    "secret": "GV3UEVQVOM4D4O33"
}

You must now log in with a otp property whose value is generated by your authenticator app.

Disable 2FA

To disable 2FA, you need to generate and use a OTP from your authenticator app.

POST /users/me/tfa/disable
{
    "otp": "123456"
}

Get once-a-month release notes & real‑world code tips...no fluff. 🐰