Ninja Signal — Technical Release Alert
16/02/2026
Build f14135e | 2026-02-16 | Production Deploy Confirmed
MFA IS LIVE. YOUR PASSWORD-ONLY LOGIN JUST GOT AN UPGRADE.
Ninja Signal now supports optional multi-factor authentication with two methods: TOTP authenticator apps and email verification codes. Every user gets 8 single-use backup codes. All of it managed from a new Security tab — no admin required.
Oh, and Niko writes your emails now. You've been warned.
--
WHAT SHIPPED
1. TOTP Authenticator Support
Scan a QR code. Enter a 6-digit code. Done.
Works with Google Authenticator, Authy, 1Password, Microsoft Authenticator — anything RFC 6238-compliant. 30-second rotation, 1-step window tolerance. Secret available for manual entry if QR isn't your thing.
2. Email Verification Codes
6-digit code delivered to your registered email on login. 10-minute expiry. 5 attempts per code before it burns. Auto-sent on password success — no extra clicks.
3. Backup Codes
8 random hex codes generated on MFA setup. Bcrypt-hashed at rest. Displayed exactly once. Each code is single-use and removed after consumption. When you're down to 2 remaining, the UI turns amber. Take the hint.
4. MFA-Pending Token Architecture
This is the part that matters for security teams:
- Successful password auth with MFA enabled issues a 5-minute JWT with mfaPending: true
- Middleware intercepts ALL requests with pending tokens
- Only two endpoints are reachable: /api/auth/mfa/verify and /api/auth/mfa/send-email-code
- Everything else — every API call, every page — returns 401 or redirects to /login
- Full session token (24h) is issued ONLY after second-factor verification
There is no client-side bypass. The gate is at the middleware layer.
5. Security Tab (All Users)
The /admin page now has a 4th tab: SECURITY. Accessible to every authenticated user, not just admins. Admin-only tabs (Users, Health, Password) remain restricted. Admin API routes unchanged.
From the Security tab you can:
- Set up TOTP (QR code + manual secret + verify)
- Set up email MFA (sends code + verify)
- View backup codes remaining
- Disable MFA (requires current code to confirm)
6. Niko-Voiced Emails
All transactional emails rewritten. Niko is the platform's AI ninja agent. The tone is... direct.
Approval email:
Subject: "[Ninja Signal] You're in. Don't make me regret it."
Includes amber MFA recommendation: "Set up MFA unless you enjoy living dangerously. And by 'dangerously' I mean 'stupidly.'"
Admin notification:
Subject: "[Ninja Signal] Incoming: {name} wants in"
Body: "Someone thinks they deserve access. I'd judge them, but I'm just an AI."
MFA code:
Subject: "[Ninja Signal] Your login code: {code}"
Body: Large styled code block. "Try not to lose it in the next 10 minutes."
Signature: "-- Niko / Ninja Signal AI . Professional Threat Whisperer . Unpaid Intern"
--
TECHNICAL SUMMARY
Stack: Next.js 16 | React 19 | FastAPI | Neo4j 5
Packages added: otpauth (TOTP generation/validation), qrcode (QR data URLs), @types/qrcode
New API routes: 8 endpoints under /api/auth/mfa/
Files changed: 19 (9 new, 10 modified)
Lines added: ~1,700
Build time: 21s compile, 31s total Docker build
New endpoints:
GET /api/auth/mfa/status — Current MFA state + backup codes remaining
POST /api/auth/mfa/setup-totp — Generate TOTP secret + QR code
POST /api/auth/mfa/confirm-totp — Verify first code, activate TOTP, return backup codes
POST /api/auth/mfa/enable-email — Send setup verification code
POST /api/auth/mfa/confirm-email — Verify code, activate email MFA, return backup codes
POST /api/auth/mfa/verify — Login MFA verification (TOTP/email/backup)
POST /api/auth/mfa/send-email-code — Resend email code during login
POST /api/auth/mfa/disable — Disable MFA (requires current code)
Design decisions:
- Email codes: in-memory Map with TTL cleanup interval. Intentionally ephemeral — codes don't survive restart and don't need to.
- TOTP secrets + hashed backup codes: persisted in user JSON store alongside existing auth data.
- Middleware enforcement: mfaPending tokens are checked BEFORE route handlers execute. No server-side route can be reached without clearing MFA.
- Non-admin /admin access: page route relaxed, API routes unchanged. Non-admins see only the Security tab.
--
WHAT'S NEXT
MFA enforcement policies (per-role, org-wide mandatory). Community mitigation ranking in the ML pipeline. KQL detection rule generation from graph intelligence. Multi-hop link prediction for threat actor attribution.
--
Ninja Signal is a graph-native threat intelligence platform. Ingests from NVD, MITRE ATT&CK, CISA KEV, AlienVault OTX, phishing feeds, and OpenCTI into a Neo4j knowledge graph. Real-time visualization. ML-powered community detection, risk scoring, and link prediction. WebSocket streaming. Patent pending.
#cybersecurity #threatintelligence #MFA #TOTP #infosec #graphdatabase #neo4j #nextjs #appsec #zerotrust
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·