Sign-in, enforced MFA, sessions, and signing out
Every portal page requires sign-in. StackJack requires multi-factor authentication (MFA) for locally authenticated users; people who sign in through your federated identity provider follow that…
Written By Christopher Scaminaci
Last updated 3 days ago
Every portal page requires sign-in. StackJack requires multi-factor authentication (MFA) for locally authenticated users; people who sign in through your federated identity provider follow that provider's authentication and MFA controls. This page covers what team admins need to know about sign-in, session lifetimes, signing out, and the identity settings you control.
How sign-in works
StackJack sign-in is powered by a dedicated identity service (Zitadel). When anyone opens the portal without a session, they're redirected to the hosted sign-in page, authenticate there (password + MFA, or your federated identity provider if you've configured one), and return to the page they originally asked for.
Setup emails and password-reset emails come from the identity service and may arrive from a zitadel.cloud address — that's expected.
MFA is enforced for local accounts
MFA enrollment is mandatory for users who authenticate locally with a StackJack password. The current identity policy forces MFA for local authentication but does not add another StackJack factor after a user authenticates through a configured external identity provider. Apply the MFA policy you require in Microsoft Entra ID, Google Workspace, Okta, or whichever provider you connect. The local enrollment walkthrough lives in Your first sign-in.
What admins should know:
- New invitees will be prompted to enroll right after setting their password — mention it when you invite people so the QR-code prompt doesn't surprise them.
- If a teammate loses their MFA device, they cannot sign in. Recovery is handled through the identity service — contact support@stackjack.io to have the factor reset.
- StackJack's current local-account methods include authenticator-app TOTP, passkeys, one-time email codes, and recovery codes. The exact prompt depends on the person's device and registered factors.
Sessions
- A portal session lasts 8 hours of activity — it slides forward while the person keeps using the portal, then requires a fresh sign-in.
- Behind the scenes, the session's access credentials are refreshed automatically; if that silent refresh ever fails, the user is sent back to sign-in rather than left in a broken half-signed-in state.
- Sessions survive StackJack maintenance and deployments — nobody is signed out by a routine release.
Signing out
Sign out lives at the bottom of the left sidebar. It ends both the portal session and the identity-service session, then returns to the portal (which redirects to sign-in). If a user only closes the browser tab, their session remains valid until it expires — for shared machines, tell your team to use Sign out.

There is no admin button to force-end another user's browser session. If you need to cut someone's access off immediately, use Revoke Access on the Team page — it kills every AI-agent access path on the next request and their portal renders an access-revoked notice instead of data (Managing members).
Identity & SSO settings you control
The Team page's Identity & SSO card links to your organization's identity console (Open Identity Portal). From there, organization owners can inspect or manage the organization-scoped settings their identity role permits, including:
- Federated single sign-on with Microsoft Entra ID, Google Workspace, or Okta — so teammates sign in with your existing corporate identity.
- Login behavior and security, including local MFA and passkey settings.
- Password complexity, password expiry, and lockout policy.
- Organization domains, domain discovery, and external identity providers.
- Organization branding, notification settings, and login/message text.
- The raw list of identity accounts in your organization.
Your organization in the identity console matches your StackJack company name — select it from the organization dropdown if prompted. (If the Team page shows an "Identity Organization Not Linked" warning instead of this card, contact support.)
Access to the identity console requires organization-owner rights, which StackJack grants to owners and co-owners. Instance-wide defaults remain reserved to StackJack operators. If the organization console refuses you access, contact support@stackjack.io to have the grant repaired.
One caution about SSO and new invitees
If a brand-new invitee signs in through your federated identity provider before opening their invite email, their identity can be created in the wrong place and the invite won't attach. Tell invitees to use the link in their invite/setup email first; if someone gets stuck this way, StackJack support can relocate the identity (they'll need to redo password setup afterward). See Inviting teammates.
More in Team & Access
Team roles and what each role can doInviting teammates: the invite lifecycle from email to first sign-inSelf-registration and approving new membersManaging members: tools, roles, suspension, and reactivationStill need help? Ask the team