Skip to content

Trusted Devices

Trusted devices let the gateway remember a browser after a successful MFA verification.

  • A trusted-device cookie is set after verification
  • Future logins skip MFA until the TTL expires (default 30 days)
  • Trust is browser-specific

You can trust a device in two ways:

  1. Complete MFA verification
  2. Check Trust this device for 30 days
  3. Finish sign-in
  1. Go to Account Security
  2. In Trusted Devices, click Trust This Device

The Trusted Devices table shows:

  • Device label
  • Last used time
  • IP address
  • Expiration

To revoke a device, click Revoke next to the entry.

Admins can set the trusted-device TTL in Settings → MFA Requirements (mfa_trusted_device_ttl_days).