New service: single sign-on
Wednesday, August 26th, 2026We're pleased to announce the release of a new feature: single sign-on for D-PHYS services. It will allow you to reuse an existing login session from one website to authenticate additional services. It will also give you the option to use passkeys to further simplify your login experience. In order to improve account security, password logins will require an MFA step (the same TOTP mechanism ETH ID uses).
Here's the timeline:
- the Authentik auth provider website is available immediately.
- in order to give you ample time to prepare your TOTP and passkeys and familiarize yourself with the auth flow, there's a 3 week grace period in which only two minor services (the LTS dashboard and [later this week] the MAC registration) use the new auth method. This way, you won't be surprised by essential services suddenly requiring MFA while still giving you two websites to play with.
- after September 21, we will start moving services from the current LDAP login to Authentik auth via OIDC. Since this migration can be quite complicated and requires thorough testing, we will perform it one service at a time, starting with Backupbox, the D-PHYS events and the mailing list interface. Afterwards, we'll migrate Roundcube webmail.
- if we encounter issues with any service, we can immediately revert to LDAP login.
So please head over to Authentik and set up your MFA token. Authentik will guide you through the process during your first login. Just use the same authenticator app you already have in place for your ETH account. If you'd like to give passkeys a go, our service documentation has all the details.

