VaultAP Docs

Authentication

VaultAP uses Clerk as its authentication provider, giving you a secure, battle-tested identity layer without the risks of a custom-built auth system.

Email and Password

Users sign in with their email address and a password. Passwords must meet the following requirements:

  • Minimum 12 characters
  • At least one uppercase letter, one lowercase letter, and one number
  • Not found in known breach databases (checked at time of creation and reset)

Passwords are never stored in plain text. Clerk handles hashing and secure storage using bcrypt.

Multi-Factor Authentication (MFA)

VaultAP supports MFA to add a second layer of protection beyond the password.

Enable MFA

Each user enables MFA from their profile settings by clicking Enable MFA.

Scan QR code

Use an authenticator app (Google Authenticator, Authy, 1Password, etc.) to scan the QR code displayed on screen.

Enter verification code

Enter the six-digit code from your authenticator app to confirm setup.

Save backup codes

VaultAP displays a set of one-time backup codes. Store these in a safe place in case you lose access to your authenticator app.

VaultAP strongly recommends enabling MFA for all users, especially Admins and Reviewers who can take action on invoices. Admins can see which users have MFA enabled on the Team Management page.

Session Management

VaultAP sessions have the following properties:

PropertyValue
Session duration24 hours of inactivity before automatic logout
Maximum session length7 days, regardless of activity
Concurrent sessionsAllowed across multiple devices
Session revocationAdmins can revoke all sessions for any user from Team Management

When a user's role is changed or their account is deactivated, all active sessions for that user are immediately invalidated.

If you suspect unauthorized access to an account, deactivate the user from Team Management. This instantly revokes all sessions and blocks further login.

SSO Readiness

Single sign-on (SSO) via SAML 2.0 and OpenID Connect is planned for V2 of VaultAP. The Clerk-based authentication layer was chosen in part because it supports a smooth upgrade path to SSO without requiring changes to VaultAP's core application.

If SSO is a requirement for your organization today, contact us at support@vaultap.com to discuss your timeline and needs.