- Login Logs – Record user IP, device, browser, and login time for tracking.
- Suspicious Login Detection – Alert user/admin for logins from new IPs or locations.
- MFA / 2FA – Add extra verification via SMS, Email, or Auth App; includes QR setup and backup codes.
- Session Timeout & Refresh Tokens – Auto-logout inactive sessions to prevent hijacking.
- Authentication Method Selection – Admin can enable/disable Password, MFA, Biometrics, or Passkeys.
- Biometrics & Passkeys Enrollment – Allow users to register Face ID, fingerprint, or passkeys with feedback.
- Password Strength Requirements – Enforce strong passwords; show live strength indicator.
- Password Rotation / Expiry – Force password updates every set period with expiry alerts.
- Password Reset / Recovery – Secure self-reset using Email/OTP and optional MFA verification.
coders