# 2FA Update - Two Factor Authentication

**URL:** https://community.baserow.io/t/2fa-update-two-factor-authentication/4255
**Category:** Feature Ideas
**Created:** [January 11, 2024, 9:33am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255 "2024-01-11T09:33:35Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![dalekirkwood](https://community.baserow.io/user_avatar/community.baserow.io/dalekirkwood/32/2157_2.png) [@dalekirkwood](https://community.baserow.io/u/dalekirkwood)
#### Post date: [January 11, 2024, 9:33am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/1 "2024-01-11T09:33:35Z")

</div>

I just wanted to check. I see the 2FA is listed on your website with an hour glass. What is the progress of 2FA?

Are there any other suggestions for security when self-hosting?

Thanks

---

<div class="post-metadata">

### Author: ![petrs](https://community.baserow.io/user_avatar/community.baserow.io/petrs/32/159_2.png) [@petrs](https://community.baserow.io/u/petrs)
#### Post date: [January 12, 2024, 2:19am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/2 "2024-01-12T02:19:52Z")

</div>

Hi @dalekirkwood,

while I don’t have any particular timeline for you regarding 2fa, one alternative is to configure Baserow with a SSO provider that has 2fa, and disable standard Baserow login. This will force users to log in using your set method.

---

<div class="post-metadata">

### Author: ![dalekirkwood](https://community.baserow.io/user_avatar/community.baserow.io/dalekirkwood/32/2157_2.png) [@dalekirkwood](https://community.baserow.io/u/dalekirkwood)
#### Post date: [January 13, 2024, 6:38pm UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/3 "2024-01-13T18:38:53Z")

</div>

Thanks Petrs

That is a great idea, I was thinking something similar - I’m glad to hear that is a viable solution.

---

<div class="post-metadata">

### Author: ![Mangaire1](https://community.baserow.io/letter_avatar_proxy/v4/letter/m/3ab097/32.png) [@Mangaire1](https://community.baserow.io/u/Mangaire1)
#### Post date: [December 11, 2024, 1:42pm UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/4 "2024-12-11T13:42:36Z")

</div>

Hi Petrs, can you tell me what the status is? Companies who are small dont see a loginprocedure with an email and a password as safe anymore.  
That means they don’t want to use Baserow.  
Where can I add: **SSO URL / Endpoint** :, the **Certificaat** and **Entity ID** :  
Thanks  
Bob

---

<div class="post-metadata">

### Author: ![petrs](https://community.baserow.io/user_avatar/community.baserow.io/petrs/32/159_2.png) [@petrs](https://community.baserow.io/u/petrs)
#### Post date: [December 11, 2024, 3:15pm UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/5 "2024-12-11T15:15:57Z")

</div>

We haven’t started on 2fa yet. To use any SSO provider you will need to be self-hosting on an enterprise license plan. In that case you can also contact our support to help you set it up.

---

<div class="post-metadata">

### Author: ![Mangaire1](https://community.baserow.io/letter_avatar_proxy/v4/letter/m/3ab097/32.png) [@Mangaire1](https://community.baserow.io/u/Mangaire1)
#### Post date: [December 11, 2024, 3:27pm UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/6 "2024-12-11T15:27:51Z")

</div>

Unfortunately…it’s is for a small company…

---

<div class="post-metadata">

### Author: ![Mangaire1](https://community.baserow.io/letter_avatar_proxy/v4/letter/m/3ab097/32.png) [@Mangaire1](https://community.baserow.io/u/Mangaire1)
#### Post date: [February 8, 2025, 7:54am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/7 "2025-02-08T07:54:28Z")

</div>

How we are doing with the 2fa for small business?

---

<div class="post-metadata">

### Author: ![petrs](https://community.baserow.io/user_avatar/community.baserow.io/petrs/32/159_2.png) [@petrs](https://community.baserow.io/u/petrs)
#### Post date: [February 10, 2025, 4:42am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/8 "2025-02-10T04:42:45Z")

</div>

Hi @Mangaire1, there are no plans to address this in Q1 2025 although it is a on a tentative plan for this year.

---

<div class="post-metadata">

### Author: ![360Creators](https://community.baserow.io/user_avatar/community.baserow.io/360creators/32/3827_2.png) [@360Creators](https://community.baserow.io/u/360Creators)
#### Post date: [February 12, 2025, 11:16am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/9 "2025-02-12T11:16:39Z")

</div>

I think it’s important as well to have 2fa.

---

<div class="post-metadata">

### Author: ![360Creators](https://community.baserow.io/user_avatar/community.baserow.io/360creators/32/3827_2.png) [@360Creators](https://community.baserow.io/u/360Creators)
#### Post date: [March 12, 2025, 3:17pm UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/10 "2025-03-12T15:17:57Z")

</div>

**Bump**

> [@Baserow security: 2FA "soon" is not soon anymore](https://community.baserow.io/t/baserow-security-2fa-soon-is-not-soon-anymore/9678):
>
> Even though I might not be a security expert, I do understand that a baserow instance could potentially be brute forced to gain access which nobody wants to happen. 2FA is that extra defensive layer. It’s already promoted on the pricing page to be coming soon. And I read [this post from Jan 2024](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255) asking about a timeline for it and it’s not there yet. This was last year… Baserow is becoming more and more important to me, and so does the security side of things. It’s not nice to have security thin…

---

<div class="post-metadata">

### Author: ![olgatrykush](https://community.baserow.io/user_avatar/community.baserow.io/olgatrykush/32/219_2.png) [@olgatrykush](https://community.baserow.io/u/olgatrykush)
#### Post date: [March 19, 2025, 3:22pm UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/11 "2025-03-19T15:22:34Z")

</div>

Hey @360Creators, 2FA should be released in Q2 🙌

---

<div class="post-metadata">

### Author: ![360Creators](https://community.baserow.io/user_avatar/community.baserow.io/360creators/32/3827_2.png) [@360Creators](https://community.baserow.io/u/360Creators)
#### Post date: [March 19, 2025, 6:39pm UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/12 "2025-03-19T18:39:20Z")

</div>

Heyy @olgatrykush! That’s really great to read!! 😁 🙏  
Thank you!!

---

<div class="post-metadata">

### Author: ![DickHoning](https://community.baserow.io/user_avatar/community.baserow.io/dickhoning/32/4153_2.png) [@DickHoning](https://community.baserow.io/u/DickHoning)
#### Post date: [May 20, 2025, 7:39am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/13 "2025-05-20T07:39:39Z")

</div>

@olgatrykush I’m really looking forward to that. Would you also consider opening op part of the notifications to the Premium plan? In order to properly protect your data, you need to be able to monitor suspicious behaviour … right?

---

<div class="post-metadata">

### Author: ![olgatrykush](https://community.baserow.io/user_avatar/community.baserow.io/olgatrykush/32/219_2.png) [@olgatrykush](https://community.baserow.io/u/olgatrykush)
#### Post date: [May 20, 2025, 10:02am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/14 "2025-05-20T10:02:08Z")

</div>

Hey @DickHoning, could you please elaborate on this? We currently have these types of [notifications](https://baserow.io/user-docs/notifications#overview), and they are free. Only [row comments](https://baserow.io/user-docs/row-commenting) is a paid feature available in the Premium plan.

---

<div class="post-metadata">

### Author: ![DickHoning](https://community.baserow.io/user_avatar/community.baserow.io/dickhoning/32/4153_2.png) [@DickHoning](https://community.baserow.io/u/DickHoning)
#### Post date: [May 20, 2025, 10:17am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/15 "2025-05-20T10:17:25Z")

</div>

Hi @olgatrykush I’m looking for log file viewer where I can see which user logged in when, what api call are made, etc.

---

<div class="post-metadata">

### Author: ![olgatrykush](https://community.baserow.io/user_avatar/community.baserow.io/olgatrykush/32/219_2.png) [@olgatrykush](https://community.baserow.io/u/olgatrykush)
#### Post date: [May 20, 2025, 12:47pm UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/16 "2025-05-20T12:47:26Z")

</div>

Hey @DickHoning, we also have an Audit log, though it only shows specific events listed here: [https://baserow.io/user-docs/admin-panel-audit-logs#events-in-the-activity-log](https://baserow.io/user-docs/admin-panel-audit-logs#events-in-the-activity-log). It does not show user login or API call details.

I’ll check with the team if there are any plans to add more events to the list. 🙂

---

<div class="post-metadata">

### Author: ![spook](https://community.baserow.io/user_avatar/community.baserow.io/spook/32/2565_2.png) [@spook](https://community.baserow.io/u/spook)
#### Post date: [June 4, 2025, 5:53am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/17 "2025-06-04T05:53:25Z")

</div>

This is not an answer to your question, but it might help.

I use this monitoring script: [Fail2Ban or similar for public App access?](https://community.baserow.io/t/fail2ban-or-similar-for-public-app-access/10238) - which alerts me of failed logins (but gives no details of the username or IP)

To compliment that, I place BaseRow behind Nginx Reverse Proxy and using Fail2Ban. BaseRow responds with a 401 when a logon fails, so monitoring the NPM logs with Fail2Ban lets me see at least the IP addresses of failed logons and also ban them.

You could also monitor the NPM logs for successful logins if you want - and possibly also API calls.

However, none of this allows you to monitor which user logs in unfortunately, but hopefully it’s something.

---

<div class="post-metadata">

### Author: ![olgatrykush](https://community.baserow.io/user_avatar/community.baserow.io/olgatrykush/32/219_2.png) [@olgatrykush](https://community.baserow.io/u/olgatrykush)
#### Post date: [June 4, 2025, 8:28am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/18 "2025-06-04T08:28:09Z")

</div>

Hi @DickHoning, we’ve also decided to add a new event to the Audit log that records when a user logs in.

Regarding API requests, we won’t add this event since it would quickly fill up the Audit log—capturing each call would generate lots of data. 🙂

---

<div class="post-metadata">

### Author: ![olgatrykush](https://community.baserow.io/user_avatar/community.baserow.io/olgatrykush/32/219_2.png) [@olgatrykush](https://community.baserow.io/u/olgatrykush)
#### Post date: [June 4, 2025, 8:28am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/19 "2025-06-04T08:28:53Z")

</div>

Thank you @spook for sharing your approach — it’s very valuable. 🙌

---

<div class="post-metadata">

### Author: ![DickHoning](https://community.baserow.io/user_avatar/community.baserow.io/dickhoning/32/4153_2.png) [@DickHoning](https://community.baserow.io/u/DickHoning)
#### Post date: [June 23, 2025, 8:51am UTC](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255/20 "2025-06-23T08:51:12Z")

</div>

Hi @olgatrykush , thanks for adding user log in events to the audit log. Is it possible to make this log available to Premium users?

[Next page](https://community.baserow.io/t/2fa-update-two-factor-authentication/4255.md?page=2)
