Skip to content

Authentication

Quackback splits authentication into two concerns: who's allowed in and how they sign in. Both live on Admin → Settings → Security → Authentication, which has three tabs:

TabControlsDoc
Portal accessVisibility, allowed domains, email invites, allowed segments, widget sign-inControl portal access and sign-in
Team accessTeam-side 2FA and the SSO summaryConfigure team security
Sign-in providersPassword, magic link, social OAuth, Custom OIDC, per-surface togglesSign-in providers

Two audiences

AudienceWho they are
Portal usersCustomers who submit and vote on feedback.
Team membersTeammates with a role (Owner, Admin, Manager, Contributor, or a custom role).

Team members can browse the public portal while signed into Quackback. The widget will not treat a team email as a customer. Use the portal login or Team access channel instead.

Portal access channels

A private portal admits visitors through these channels, evaluated in order:

ChannelWho it lets inRequires
TeamTeam membersSigned in on Quackback (admin or portal login)
Allowed domainAnyone whose verified email matches a listed domainEmail verified
Email inviteA specific person you invitedEmail verified
Allowed segmentAny member of a permitted segmentEmail verified
Widget sign-inA visitor already identified in your embedded widgetIdentify + Widget sign-in toggled on

See Control portal access for the full setup walkthrough.

Sign-in methods

MethodPortal usersTeam members
PasswordYes (on by default)Yes (on by default)
Magic linkOptional (off by default)Yes (on by default)
OAuth social10 providers (Apple, Discord, Facebook, GitHub, GitLab, Google, LinkedIn, Microsoft, Reddit, Twitter / X)Same 10 providers - GitHub and Google on by default
Custom OIDC (portal button)One OIDC button on the portal sign-in form, tier-gatedUse full team SSO instead
Single sign-onRoutes via verified-domain dispatchVerified domains, optional enforcement, JIT provisioning

Each method is a toggle. Turn on the combination that fits your users. At least one method always stays enabled per surface.

Team security

The Security page adds protections specific to the team:

  • Two-factor authentication: TOTP codes on top of a password, optionally required workspace-wide.
  • Single sign-on: connect an OIDC provider, verify your domains, and require SSO so company emails can only sign in through your IdP.
  • Recovery codes: break-glass sign-in when SSO is unavailable.
  • Audit log: an append-only record of every security-sensitive change.

Sign-in hardening

Quackback rate-limits password and magic-link sign-in attempts per IP and email address, tracks devices, and emails the account owner the first time an account signs in from a new device. The new-device email is on by default and configurable on the Team tab.

Sessions

  • Sessions last 7 days and refresh every 24 hours on activity.
  • Signing out invalidates the session immediately.
  • Sessions are stored in PostgreSQL and expired ones are cleaned up automatically.

Session types

Signing in only unlocks the place someone signed in from. A customer who uses the widget never gets admin dashboard access from that sign-in, even if you later invite them to your team.

TypeHow someone gets itWhat they can do
QuackbackSigns in at your Quackback URL (admin login or the portal login form)Team access for their role if they are a team member; otherwise customer access
WidgetUses your embedded widget (as a guest or after identify)Customer actions in the widget only, not exports, settings, or the admin inbox
Portal from widgetOpens the portal from a verified widget session with Widget sign-in onCustomer access on the portal, still not admin
Guest or identify in the widget  →  Widget
        │
        │  Opens the portal (Widget sign-in on)
        ▼
                   Portal from widget
 
Signs in at Quackback            →  Quackback (separate)

You cannot identify a team member through the widget. If the signed identity matches a team member, identify returns IDENTITY_NOT_ALLOWED. Invite them to use the portal login or admin login instead. If a customer is later added to your team, their existing widget or portal-from-widget sign-in stays a customer sign-in until they sign in on Quackback itself.

Roles

RoleCapabilities
UserSubmit, vote, and comment on the public portal.
MemberEverything a user can do, plus access the admin dashboard and manage feedback.
AdminEverything a member can do, plus workspace settings, team management, and integrations.

See Roles & permissions for the full breakdown.

Next steps