Lymeno now supports two-factor authentication and API tokens
Protect sign-in with an authenticator app, and automate your workflows with workspace API tokens.
Two-factor authentication
Turn on Two-factor authentication under Profile & security. After you confirm your password, scan the QR code with an authenticator app or enter the setup key, and then enter the 6-digit code to finish.
You receive 10 backup codes, each usable once, for when your authenticator app is not available. Choosing New backup codes replaces all existing codes. When you sign in, you can trust a device for 30 days.
API tokens
Workspace owners and admins can create API tokens under Settings → API tokens. Each token has:
- An access level: Read only, or Read and write, which can do everything an admin can except manage API tokens.
- An expiration: 30 days, 90 days (the default), 1 year, or never.
The token is shown only once. Send it in the Authorization: Bearer header. API tokens cannot create or revoke other tokens, and every change made with a token is recorded in the audit log under the token’s name.
To limit what an agent can do inside the database as well, read Give every agent its own expiring database role.