How two-factor authentication via the Candis app works
Two-factor authentication, or 2FA, adds a second authentication factor to your email address and password. With our recommended method, Candis sends a push notification to the Candis app on your smartphone.
As soon as you start using the Candis app and log in to the app once, Candis automatically activates push notifications as your second authentication factor. You do not need to change any additional settings in Candis.
Two-factor authentication via the Candis app is stored as the default method for all users of the Candis app. You can still choose another available authentication method during every login.
Please note: Two-factor authentication via the Candis app protects your Candis web login. You use the app to confirm the login in your browser.
Requirements
You need to meet the following requirements to confirm your web login via push notification:
You have installed the Candis app on your smartphone.
You use at least version 2.1 of the Candis app.
You have logged in to the Candis app at least once with your email address and password.
You have access to your smartphone when you log in to Candis in your browser.
You have enabled push notifications for the Candis app in your smartphone settings.
Tip: Check the app version on your smartphone. Update the Candis app in the App Store or Google Play Store if you use a version older than 2.1.
Tip: Enable push notifications for the Candis app on your smartphone. This ensures that you receive login requests immediately on your lock screen or in your notification center.
Confirming your web login with the Candis app
Open Candis in your browser and log in with your email address and password.
Candis displays the message Waiting for your approval.
Open the push notification on your smartphone.
The Candis app opens the Confirm login attempt section.
Check the login details. The Candis app shows the account name, device, and browser used, for example Chrome on Mac OS X.
Tap Confirm if the details match your current web login.
Candis completes the web login in your browser automatically.
You can save the two-factor authentication for 14 days on the device you are using. Select the corresponding option during login. Candis will not request two-factor authentication again on this device for the next 14 days.
Please note:
Save two-factor authentication only on personal and trusted devices.
Tap Reject if you did not initiate the displayed login attempt. This prevents another person from logging in with your credentials. Change your password afterwards.
Using an alternative method when your smartphone is unavailable
You can switch to an alternative authentication method if you do not have access to your smartphone or the Candis app.
You can also choose an alternative authentication method if the Candis app is stored as your default method and you prefer to use another option.
Start the web login with your email address and password.
Select Or try another way on the login page.
Choose an alternative authentication method.
Request the code by SMS or email.
Enter the code on the login page to complete the web login.
Tip: Use this alternative when you cannot access the Candis app. Login via push notification remains the recommended method.
Viewing your 2FA method and last app login in your profile
Your profile shows which two-factor authentication method is stored for your user account. You can also see your most recent login to the Candis app.
Open your profile in Candis.
Check the stored 2FA method.
Check the date and time of your most recent login to the Candis app.
Viewing app usage in user management
As an admin, you can check which team members already use the Candis app in user management.
Open user management.
Find the relevant team member.
Look for the app icon next to the team member.
The app icon shows that the team member already uses the Candis app.
Inviting team members to the Candis app
As an admin, you can invite individual team members or all team members to the Candis app.
Open user management.
Move your cursor over the relevant team member.
Click Invite to app in the menu that appears.
Confirm the invitation in the pop-up window.
You can also invite all team members to the Candis app from the pop-up window.
Using the Candis app to display credit card details
Once you have set up and logged in to the Candis app, Candis also uses the app to securely display credit card details.
When you request to display credit card details in the web application, Candis sends a request to the Candis app. Confirm the request in the app to display the credit card details in your browser.
Examples
Confirming a web login during your working day
You open Candis in your browser, enter your email address and password, and receive a push notification on your smartphone. You check the device and browser in the Candis app and tap Confirm. Candis logs you in to the web application.
Rejecting a login attempt
You receive a push notification even though you are not currently logging in to Candis. You open the Candis app, check the login attempt, and tap Reject. You then change your password.
Displaying credit card details securely
You want to view credit card details in the web application. Candis sends a confirmation request to the Candis app. You confirm the request on your smartphone, and Candis displays the credit card details in your browser.
Please note: You cannot currently confirm credit card payments using the Candis app.
FAQ's
What can I do if I do not receive a push notification?
Open the Candis app manually and check your internet connection. Make sure that push notifications for the Candis app are enabled and that you are signed in to the app with the same account you use for the web sign-in.
Can I send the push notification again?
Select Send again if Candis shows this option on the sign-in page. Otherwise, restart the sign-in or select Try another way.
What can I do if the sign-in request has expired?
Restart the sign-in to receive a new request. Only confirm the latest sign-in request.
Can I sign in without the Candis app?
Yes. If you do not use the Candis mobile app yet, you can choose another supported 2FA method. Two-factor authentication through the Candis app is only available after you have signed in to the mobile app.
What should I do if I receive an unknown sign-in request?
Select Reject and change your Candis password. Never confirm a sign-in request that you did not initiate.
What can I do if I have lost or replaced my phone?
Install the Candis app on your new phone and sign in once. Select Try another way if you no longer have access to your previous phone.
