Security

FlamingoFlow Security

Security console

The single admin account that gates this panel - credentials, two-factor, live sessions, and the audit trail.

2 need attention

Security posture

Live checks across credentials, crypto, and transport

Admin password

Stored as an Argon2id hash. The environment seed is no longer used.

Two-factor authentication

Not enabled. Add an authenticator app for a second factor.

Encryption key

A 32-byte APP_ENCRYPTION_KEY is configured.

HTTPS

This request is encrypted; cookies are marked Secure.

Login gate

AUTH_BYPASS is on (demo). The dashboard renders without a login.

Secure storage

Credential and session state can be persisted.

Admin password

Last changed in 1w

Minimum 10 characters. Other sessions are signed out on change.

Two-factor authentication

Time-based one-time codes (TOTP)

Off

Add a second factor

After your password, the login will ask for a rotating 6-digit code from your phone. Strongly recommended for an account holding client ad data.

Active sessions

3 signed-in devices

  • Chrome on Windows

    24.150.56.86 active in 1w

  • Chrome on Windows

    108.170.138.97 active in 1w

  • Chrome on Windows

    104.28.161.124 active in 1w

Login attempts

Most recent first

  • Signed in

    108.170.138.97

    in 1w
  • Signed in

    24.150.56.86

    in 1w
  • Wrong password

    24.150.56.86

    in 1w
  • Signed in

    104.28.161.124

    in 1w

Audit trail

Security-relevant actions

  • CSRF token rejected

    13.239.147.237

    in 3w
  • CSRF token rejected

    13.239.147.237

    in 3w
  • CSRF token rejected

    13.239.147.237

    in 3w
  • CSRF token rejected

    13.239.147.237

    in 3w
  • Signed in

    108.170.138.97

    in 1w
  • Signed in

    24.150.56.86

    in 1w
  • Login failed

    24.150.56.86

    in 1w
  • Signed out

    108.170.138.97

    in 1w
  • Signed in

    104.28.161.124

    in 1w
  • Signed out

    104.28.161.124

    in 1w