Skip to content
SkyKeephelp

Signing in to the vault

Sign-in starts with your password. Whether it then asks for a one-time

code, delivered to the email address on your account, is a policy rather

than a fixed second step: each account holds a preference, an

administrator can require the code of everybody, and the shipped default

after enrolment is not to ask. Your sign-in name is just a name, and

codes never go anywhere the vault was not explicitly told about. The vault

is deliberately unrevealing to outsiders — a refused sign-in says "bad

username or password" and nothing else, the same sentence whether the

name was unknown, the password wrong, the account disabled or locked, or

the account has no address to send a code to, so nobody can probe which

identifiers exist — while every attempt, allowed or refused, lands in the

audit trail. Every attempt also takes the same three seconds, whether it

worked or not, so the clock is not an answer either. Codes are single-use

and short-lived, and a disabled account cannot begin a new sign-in at

all. Two sign-ins are password-only

whatever any preference says, for opposite reasons. An account still

awaiting its forced first password change gets a session that can do

nothing but set the new password (and the account's email). And an

account enrolled with the code turned off is simply not asked for one —

that is the ordinary rule applied to an ordinary choice, and it is how

the demonstration vault's accounts sign in.

A wrong password is refused, and says only thatstack

Every refusal reads the same, whatever was actually wrongstack

A one-time code cannot be used twicestack

An expired code is refusedstack

A disabled account cannot begin a new sign-instack

An account with no email on file cannot sign in, and reveals nothingstack