Signing in, MFA and session expiry

How authentication works, how to enrol in multi-factor authentication, and why you get signed out.

Written for
Everyone
Reading time
1 min
Last reviewed
August 4, 2026

Sign-in goes through Naveera's identity service using your work email address and password. If your organization has single sign-on configured, use the SSO route instead — your password is then managed by your own identity provider, not by Naveera.

Enrolling in multi-factor authentication

  1. Open Settings and choose Security.
  2. Start MFA enrolment. A QR code is shown once.
  3. Scan it with an authenticator app that supports time-based one-time passwords.
  4. Enter the six-digit code the app generates to confirm the pairing.
  5. Store the recovery codes somewhere you can reach without your phone.

Once enrolled, you are challenged for a code after your password. You can mark a device as remembered so the challenge is skipped on that browser for a period set by your administrator.

Why you were signed out

Access tokens are short-lived and refreshed silently while you are working. A refresh only fails if you have been idle beyond the limit, an administrator has ended your sessions, or your role or organization membership changed — in which case you are returned to sign-in so the new permissions load cleanly rather than being applied to a half-stale session.

Related

Still stuck?

Technical documentation

API references, data model, webhook payloads and integration guides — the detail behind the workflows described here. Available to signed-in Naveera customers.

Open documentation

Ask your team

Support requests are raised from inside Naveera Console, where your organization and your role are already known — which means the answer can be about your configuration rather than the general case.

Settings → Support, or ask your organization’s administrator