Authentication
Quackback splits authentication into two concerns: who's allowed in and how they sign in. Both live on Admin → Settings → Security → Authentication, which has three tabs:
| Tab | Controls | Doc |
|---|---|---|
| Portal access | Visibility, allowed domains, email invites, allowed segments, widget sign-in | Control portal access and sign-in |
| Team access | Team-side 2FA and the SSO summary | Configure team security |
| Sign-in providers | Password, magic link, social OAuth, Custom OIDC, per-surface toggles | Sign-in providers |
Two audiences
| Audience | Who they are |
|---|---|
| Portal users | Customers who submit and vote on feedback. |
| Team members | Teammates with a role (Owner, Admin, Manager, Contributor, or a custom role). |
Team members can browse the public portal while signed into Quackback. The widget will not treat a team email as a customer. Use the portal login or Team access channel instead.
Portal access channels
A private portal admits visitors through these channels, evaluated in order:
| Channel | Who it lets in | Requires |
|---|---|---|
| Team | Team members | Signed in on Quackback (admin or portal login) |
| Allowed domain | Anyone whose verified email matches a listed domain | Email verified |
| Email invite | A specific person you invited | Email verified |
| Allowed segment | Any member of a permitted segment | Email verified |
| Widget sign-in | A visitor already identified in your embedded widget | Identify + Widget sign-in toggled on |
See Control portal access for the full setup walkthrough.
Sign-in methods
| Method | Portal users | Team members |
|---|---|---|
| Password | Yes (on by default) | Yes (on by default) |
| Magic link | Optional (off by default) | Yes (on by default) |
| OAuth social | 10 providers (Apple, Discord, Facebook, GitHub, GitLab, Google, LinkedIn, Microsoft, Reddit, Twitter / X) | Same 10 providers - GitHub and Google on by default |
| Custom OIDC (portal button) | One OIDC button on the portal sign-in form, tier-gated | Use full team SSO instead |
| Single sign-on | Routes via verified-domain dispatch | Verified domains, optional enforcement, JIT provisioning |
Each method is a toggle. Turn on the combination that fits your users. At least one method always stays enabled per surface.
Team security
The Security page adds protections specific to the team:
- Two-factor authentication: TOTP codes on top of a password, optionally required workspace-wide.
- Single sign-on: connect an OIDC provider, verify your domains, and require SSO so company emails can only sign in through your IdP.
- Recovery codes: break-glass sign-in when SSO is unavailable.
- Audit log: an append-only record of every security-sensitive change.
Sign-in hardening
Quackback rate-limits password and magic-link sign-in attempts per IP and email address, tracks devices, and emails the account owner the first time an account signs in from a new device. The new-device email is on by default and configurable on the Team tab.
Sessions
- Sessions last 7 days and refresh every 24 hours on activity.
- Signing out invalidates the session immediately.
- Sessions are stored in PostgreSQL and expired ones are cleaned up automatically.
Session types
Signing in only unlocks the place someone signed in from. A customer who uses the widget never gets admin dashboard access from that sign-in, even if you later invite them to your team.
| Type | How someone gets it | What they can do |
|---|---|---|
| Quackback | Signs in at your Quackback URL (admin login or the portal login form) | Team access for their role if they are a team member; otherwise customer access |
| Widget | Uses your embedded widget (as a guest or after identify) | Customer actions in the widget only, not exports, settings, or the admin inbox |
| Portal from widget | Opens the portal from a verified widget session with Widget sign-in on | Customer access on the portal, still not admin |
Guest or identify in the widget → Widget
│
│ Opens the portal (Widget sign-in on)
▼
Portal from widget
Signs in at Quackback → Quackback (separate)You cannot identify a team member through the widget. If the signed identity matches a team member, identify returns IDENTITY_NOT_ALLOWED. Invite them to use the portal login or admin login instead. If a customer is later added to your team, their existing widget or portal-from-widget sign-in stays a customer sign-in until they sign in on Quackback itself.
Roles
| Role | Capabilities |
|---|---|
| User | Submit, vote, and comment on the public portal. |
| Member | Everything a user can do, plus access the admin dashboard and manage feedback. |
| Admin | Everything a member can do, plus workspace settings, team management, and integrations. |
See Roles & permissions for the full breakdown.
Next steps
- Set up magic-link sign-in: passwordless email sign-in
- Set up OAuth providers: social login
- Set up single sign-on: enterprise SSO with domain enforcement
- Configure team security: 2FA and the audit log
- Identify widget users: attribute widget activity to signed-in customers