Home › Blog

Ninja Signal — Technical Release Alert

16/02/2026

Build f14135e | 2026-02-16 | Production Deploy Confirmed


MFA IS LIVE. YOUR PASSWORD-ONLY LOGIN JUST GOT AN UPGRADE.

Ninja Signal now supports optional multi-factor authentication with two methods: TOTP authenticator apps and email verification codes. Every user gets 8 single-use backup codes. All of it managed from a new Security tab — no admin required.

Oh, and Niko writes your emails now. You've been warned.

--

WHAT SHIPPED

1. TOTP Authenticator Support

Scan a QR code. Enter a 6-digit code. Done.

Works with Google Authenticator, Authy, 1Password, Microsoft Authenticator — anything RFC 6238-compliant. 30-second rotation, 1-step window tolerance. Secret available for manual entry if QR isn't your thing.

2. Email Verification Codes

6-digit code delivered to your registered email on login. 10-minute expiry. 5 attempts per code before it burns. Auto-sent on password success — no extra clicks.

3. Backup Codes

8 random hex codes generated on MFA setup. Bcrypt-hashed at rest. Displayed exactly once. Each code is single-use and removed after consumption. When you're down to 2 remaining, the UI turns amber. Take the hint.

4. MFA-Pending Token Architecture

This is the part that matters for security teams:

- Successful password auth with MFA enabled issues a 5-minute JWT with mfaPending: true

- Middleware intercepts ALL requests with pending tokens

- Only two endpoints are reachable: /api/auth/mfa/verify and /api/auth/mfa/send-email-code

- Everything else — every API call, every page — returns 401 or redirects to /login

- Full session token (24h) is issued ONLY after second-factor verification

There is no client-side bypass. The gate is at the middleware layer.

5. Security Tab (All Users)

The /admin page now has a 4th tab: SECURITY. Accessible to every authenticated user, not just admins. Admin-only tabs (Users, Health, Password) remain restricted. Admin API routes unchanged.

From the Security tab you can:

- Set up TOTP (QR code + manual secret + verify)

- Set up email MFA (sends code + verify)

- View backup codes remaining

- Disable MFA (requires current code to confirm)

6. Niko-Voiced Emails

All transactional emails rewritten. Niko is the platform's AI ninja agent. The tone is... direct.

Approval email:

Subject: "[Ninja Signal] You're in. Don't make me regret it."

Includes amber MFA recommendation: "Set up MFA unless you enjoy living dangerously. And by 'dangerously' I mean 'stupidly.'"

Admin notification:

Subject: "[Ninja Signal] Incoming: {name} wants in"

Body: "Someone thinks they deserve access. I'd judge them, but I'm just an AI."

MFA code:

Subject: "[Ninja Signal] Your login code: {code}"

Body: Large styled code block. "Try not to lose it in the next 10 minutes."

Signature: "-- Niko / Ninja Signal AI . Professional Threat Whisperer . Unpaid Intern"

--

TECHNICAL SUMMARY

Stack: Next.js 16 | React 19 | FastAPI | Neo4j 5

Packages added: otpauth (TOTP generation/validation), qrcode (QR data URLs), @types/qrcode

New API routes: 8 endpoints under /api/auth/mfa/

Files changed: 19 (9 new, 10 modified)

Lines added: ~1,700

Build time: 21s compile, 31s total Docker build

New endpoints:

GET /api/auth/mfa/status — Current MFA state + backup codes remaining

POST /api/auth/mfa/setup-totp — Generate TOTP secret + QR code

POST /api/auth/mfa/confirm-totp — Verify first code, activate TOTP, return backup codes

POST /api/auth/mfa/enable-email — Send setup verification code

POST /api/auth/mfa/confirm-email — Verify code, activate email MFA, return backup codes

POST /api/auth/mfa/verify — Login MFA verification (TOTP/email/backup)

POST /api/auth/mfa/send-email-code — Resend email code during login

POST /api/auth/mfa/disable — Disable MFA (requires current code)

Design decisions:

- Email codes: in-memory Map with TTL cleanup interval. Intentionally ephemeral — codes don't survive restart and don't need to.

- TOTP secrets + hashed backup codes: persisted in user JSON store alongside existing auth data.

- Middleware enforcement: mfaPending tokens are checked BEFORE route handlers execute. No server-side route can be reached without clearing MFA.

- Non-admin /admin access: page route relaxed, API routes unchanged. Non-admins see only the Security tab.

--

WHAT'S NEXT

MFA enforcement policies (per-role, org-wide mandatory). Community mitigation ranking in the ML pipeline. KQL detection rule generation from graph intelligence. Multi-hop link prediction for threat actor attribution.

--

Ninja Signal is a graph-native threat intelligence platform. Ingests from NVD, MITRE ATT&CK, CISA KEV, AlienVault OTX, phishing feeds, and OpenCTI into a Neo4j knowledge graph. Real-time visualization. ML-powered community detection, risk scoring, and link prediction. WebSocket streaming. Patent pending.

ninjasignal.ninja

#cybersecurity #threatintelligence #MFA #TOTP #infosec #graphdatabase #neo4j #nextjs #appsec #zerotrust

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing