Security

MFA readiness, session audit, IP allowlist, secrets, CSRF/rate-limit readiness, and production locks.

MFA

totp-ready

warn

Session audits

0

Managed access

Create support, sales, admin, developer, or tenant accounts directly. Super Admin sets the password, so the user does not need to self-register.

EmailRoleStatusPasswordSourceGrantedControls
Configured in MOPITU_ALLOWED_SUPER_ADMIN_EMAILS.
super-adminactiveEnv secretenvironment
cloudflare-worker-env
6/30/2026, 7:00:00 PM
Worker env locked

Tenant registration and login activity

Track every registration intent, provider click, login attempt, failed login, and successful sign-in with location and device context. Passwords are never collected.

Total
0
Successful
0
Failed
0
Countries
0
TimeEventStatusUserSourceLocationIPDevice
No login or registration events yet.

Readiness checks

CheckStatusDetail
Persistence modewarnEmbedded runtime store, connect production database before launch
Database URLwarnRunning embedded runtime store
Stripe secretwarnStripe secret missing
Stripe webhook secretwarnWebhook secret missing
Key encryption secretwarnUsing fallback development secret
Session secretwarnUsing fallback development secret
IP allowlistwarnNo allowlist configured

Session audit

AdminEventIPDate
No records available.