Connect an AI assistant
Your AI assistant can read this documentation directly, so it answers from the current content instead of guessing. Add one of the servers below to your client — they use the Model Context Protocol (MCP). Each one covers a different body of content, so add the one you need.
The catalog did not load. Refresh the page to try again.
Loading…
{{server.name}}
{{server.summary}}
{{server.documentCount.toLocaleString()}} pages Not published to this site
- Name
-
{{server.name}} - URL
-
{{mcpServerUrl(server.path)}}
| Tool | What it does |
|---|---|
{{tool.name}} |
{{part.text}}{{part.text}} |
How can we help?
Searching in {{docApp.searchFilterBySpecificBookTitle}}
Searching for:
{{docApp.searchResultFilteredItems.length}} results for:
{{docApp.currentResultsSearchText}}
in {{docApp.searchFilterBySpecificBookTitle}}
Found {{docApp.searchResponse.totalResultsAvailable}} matches. Showing the top {{docApp.searchResponse.results ? docApp.searchResponse.results.length : 0}}. Use a more specific search to further narrow down the results.
No documentation pages match this search, so all content types are shown.
Most matches are in {{docApp.searchDocTypeRescue.best.name}}.
There is no book with the ID "{{docApp.searchBookRescue.bid}}", so the book filter from this link was ignored and results from all books are shown.
You have an odd number of " characters in your search terms - each one needs closing with a matching " character!
-
{{resultItem.title}} {{resultItem.matchedBy === 'semantic' ? 'semantic' : (resultItem.matchedBy === 'both' ? 'keyword + semantic' : 'keyword')}}
{{resultItem.url}}
{{docApp.libraryHomeViewProduct.title || docApp.libraryHomeViewProduct.id}}
{{docApp.libraryHomeViewProduct.description}}
{{group.title || group.id}}
{{group.description}}
Hornbill supports two-factor authentication (2FA) for both user and guest accounts.
2FA can either be enabled for all accounts, or on an account-by-account basis.
Hornbill provides 2FA either via an Emailed code or Authenticator App of the user’s choice (For example Microsoft’s Authenticator or Google Authenticator)
Before you begin
- Hornbill must have an email domain set up for outbound routing
- Users must have a valid email address on their account
- 2FA is only applicable to the web apps. It is not available on the native mobile apps.
- When using SSO, Hornbill 2FA is not used. Instead, 2FA should be set up using your identity provider if the option is available.
How Two-Factor Authentication Works
With Two-factor Authentication (2fa) enabled, when a user (guest) logs in to Hornbill, they will be prompted to enter a 6-digit authentication code.
The user retrieves this code from an email sent to their account’s email address or via the Authenticator App, and uses it to complete the log in process.

Settings
2FA Timeouts are set in Advanced System Settings.
Tip
To access any of the settings described in this document, open Configuration and search by part or all of the setting name
| Name | Description | Default |
|---|---|---|
| security.guest.2fa.timeout | The number of seconds a 2FA challenge token remains valid (in seconds) | 300 |
| security.user.2fa.timeout | The number of seconds a 2FA challenge token remains valid (in seconds) | 300 |
2FA mode optional
When either the user or guest mode settings are set to optional the option to enable 2FA on an individual user account is available.
- Disabled
2FA is not enabled. - Email
2FA is enabled. Authentication codes are sent to the users by email. - Authenticator App
2FA is enabled. Authentication codes are available in the Authenticator App of the user.
How to enable Email 2FA on a user account
- Using the Configuration search, type the name of the user to be changed to 2FA.
- In the list of results, select the user name.
- On the Details tab of the user account, locate the Security Settings section.
- Under Two-Factor Authentication select `Email’.
- Save Changes.
How to enable Email 2FA on a guest account
- Using the Configuration search, type
Guest. - In the list of results, click on
Guest Accounts. - In the list of guest accounts, select the account to be changed to 2FA.
- Click on the Two-Factor Authentication icon in the toolbar.
- Select
Email.
How to enable 2FA on the Authenticator App
Unlike Email which can be configured without the user, the Authenticator app requires the user to scan a QR code in the Authenticator app of their choice so must be completed by the user.
- Login as the User
- Go to the Users Profile Settings Authentication tab
- Change Type to Authenticator App
- Follow the On Screen prompts to Scan the QR code in your chosen Authenticator App then Enter the One time code in the fields provided
- Version {{docApp.book.version}}
- Node {{docApp.node}} / {{docApp.build}}