Skip to content

Guide

Community security settings

Branding & settings · 5 min read

Your community's security settings control how people prove who they are when they sign up and sign in: email verification, two-factor authentication (2FA), a CAPTCHA against spam sign-ups, and the login providers members can use. It also covers signing members out and tracking security changes.

Who can do this: Community owners and admins. Moderators and billing admins can't open Settings. · Where: Web (admin console). The settings apply on the web and in the Mateflow app. · Plan: The Security page is available on every platform plan. Single sign-on (SSO), your own social login credentials, and the audit log depend on your platform plan.

Open the community security settings

Go to Admin → Settings → Security. The page, Security & Spam Protection, has two sections:

  • Authentication: Require Email Verification and Enable Two-Factor Authentication.
  • Spam Protection: Enable Turnstile CAPTCHA.

After changing anything, click Save Changes at the bottom of the page.

Your own Mateflow account's security is separate: Dashboard (app.mateflow.com) → Settings → Security.

Require email verification for new members

Require Email Verification ("Users must verify their email address") decides whether people who sign up must prove they own their email address with a code sent to it.

  • On: new members verify their email address before their account is created.
  • Off: people who sign up with email, or who add an email after a social login that didn't provide one, aren't asked for a code. If Enable Turnstile CAPTCHA is on, a sign-up without a code must pass the Turnstile check.

Either way, paid sign-ups always require a verification code, and invitations sent by email count as verified. Social login that provides an email, and SSO, use the email from the provider.

A member who joins without verifying their email can't apply for a verification badge until their email is verified. They can verify it later by changing their email address in Settings → Security (Change Email) and confirming the new one. See Review member verification requests.

Let members turn on two-factor authentication (2FA)

Enable Two-Factor Authentication ("Allow users to enable 2FA for their accounts") lets everyone, including you and your team, add two-factor authentication (two-step verification) to their account. With it on, each person sets it up in Settings → Security on the web or in the Mateflow app. See Turn on two-factor authentication.

  • The switch makes 2FA available. It doesn't make 2FA mandatory: each person decides whether to turn it on.
  • Once someone has 2FA on, every sign-in method asks for a code: password, email link, social login, and SSO.
  • Turning the switch off stops new people from setting up 2FA. Members who already use it are still asked for a code until they turn it off themselves.
  • Admins can't reset a member's 2FA. A member who has lost both their authenticator app and their recovery codes should contact Mateflow support.

Block spam sign-ups with a Turnstile CAPTCHA

Enable Turnstile CAPTCHA adds a Cloudflare Turnstile check (a CAPTCHA) to stop bots. With it on, people complete the check when they sign up, sign in, request a sign-in link by email, or reset their password, on the web and in the Mateflow app. You need your own Cloudflare account.

  1. In Cloudflare, create a Turnstile widget and add your community's domain to it, plus your custom domain if you use one.
  2. In Admin → Settings → Security, turn on Enable Turnstile CAPTCHA.
  3. Under Turnstile Configuration, paste the widget's Turnstile Site Key and Turnstile Secret Key.
  4. Click Save Changes, then open your sign-up page once to check that the widget loads.

Saving checks only the secret key. If Cloudflare rejects it, you see "Cloudflare rejected this secret key. Check that you copied it from the same widget as the site key."

Whether or not Turnstile is on, sign-in pauses after too many failed attempts: "Too many failed attempts." and a countdown.

Choose how members sign in: social login and SSO

Login providers are set on two other pages under Admin → Settings:

  • Social Login: let members sign in with Google, Apple, Facebook, or X, and choose a Login Mode: Optional, Preferred, or Social Only. See Set up social login.
  • SSO: connect your organization's identity provider with SAML 2.0 or OIDC single sign-on and choose a login policy, such as SSO Only. Add a recovery admin before you choose SSO Only. See Set up single sign-on (SSO).

Sign members out of their sessions

Go to Admin → Members → Sessions (User Sessions) to see where people are signed in, with the device, location, Last Activity, and status. From a session's menu, choose Terminate Session to sign the person out of that device, or Terminate All User Sessions to sign them out everywhere. To end several at once, select them and click Terminate Selected.

On a member's page, Active sessions has Sign out all. Signing someone out doesn't change their account; they can sign in again. To keep someone out, see Ban, suspend, or restrict a member.

Track security changes in the audit log

The audit log records security-related actions, such as login provider changes and impersonation (viewing the community as a member). In Admin → Moderation → Audit Log, filter by the Security or Settings category. See Use the audit log.

Related articles

Was this guide helpful?

Back to guides

Can't find what you need?

If you're a member of a community, its admins are the right people to ask. If you're building or running one on Mateflow, our team can help.

Start free trial