Skip to content
Back to Support

Account Security

Two-factor authentication and devices

Two-factor authentication is available in Settings and is verified on every request to your content rather than once at sign-in. A verified device is recognized for 30 days and can be revoked at any time. This page states how each mechanism behaves and what it does not cover.

Account security in Calamus rests on three mechanisms: a second factor at sign-in, recognition of the devices you use, and re-verification of your password before it can be changed. Each is described below, including its limits.

Enabling two-factor authentication

Enable it in Settings, under Security. Enrollment requires scanning a QR code, so it is performed in the browser; once enabled it is enforced everywhere, including in the Mac and iPad applications. Any standard authenticator application works, including Google Authenticator, Authy and 1Password.

The code is generated on your device and verified on ours. Nothing is sent by email or SMS, so there is no message to intercept. Where no authenticator is configured, a six-digit code is sent to the address on the account instead.

Where the second factor is checked

On every request to your content, not only at the sign-in form. A session that has not satisfied the second factor does not reach your manuscripts, so a session token copied from a signed-in browser is not sufficient on its own. Disabling two-factor authentication requires your password.

Recognized devices

Signing in from a browser Calamus has not seen requires one additional verification. Answering it recognizes that browser for 30 days, after which it verifies again. An emailed verification code expires after ten minutes, is bound to the browser that requested it, and can be used once.

Settings, under Security, lists the devices your account is recognized on, with the time each was last seen and when its recognition expires. Revoking one takes effect immediately and can be done from any device. Revoked and expired entries remain in the list, so the history of access to the account stays readable.

The limit worth knowing

Recognition expires with the device cookie and not before. A laptop that is lost or stolen therefore remains recognized for the remainder of its 30 days unless it is revoked. Revoking it is the action that ends that access, and it is available from any other device on the account.

A recognized device appearing on a different network is recorded and nothing further happens. You are not asked to verify again for travel, for a virtual private network, or for a change of country.

Changing your password

Settings, under Security, requires your current password, the new password, and a confirmation. The current password is verified before the change is saved. Repeated failed attempts are throttled by IP address and by account.

What is recorded

Sign-ins, failed sign-ins, device verifications and revocations, export downloads and account deletion are written to a security log with the originating IP address and browser. It contains no part of your writing, and no screen displays it. Every field is listed in the Privacy Policy.