Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Strengthening GitLab.com security: Mandatory multi-factor authentication

Blog post from GitLab

Post Details
Company
Date Published
Author
Kim Waters
Word Count
499
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab is enhancing security on GitLab.com by mandating multi-factor authentication (MFA) for all users and API endpoints that authenticate using a username and password, as part of its Secure by Design commitment to combat credential stuffing and account takeover attacks. This requirement applies to users who sign in with a username and password, but not to those using social sign-on or single sign-on, unless they also have a password for direct login. The MFA rollout will occur gradually over the coming months, with notifications provided via email and in-product reminders, allowing users to prepare and minimize disruptions. Users are advised to set up MFA methods like passkeys, authenticator apps, or WebAuthn devices, and to securely save recovery codes. For API authentication, switching to personal access tokens is recommended. Failure to enable MFA by the deadline will prevent account access, and password-based CI/CD pipelines or automations will require adjustments unless using personal access or deploy tokens.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.