ES EN

Trusted addresses

A stolen password works from anywhere in the world. A list of trusted addresses changes that: from your office you sign in quickly, and from anywhere else something more than the password is required. This chapter explains how it works and how to set it up.

What is required from where

The rule is short. From an address on your list you sign in with username and password, nothing else: being there already proves who you are, so the place acts as the second step.

From any other address you need the password AND a second proof: quick access with your device (fingerprint, face or PIN) or the six-digit code from your authenticator app. If your account has neither configured, you cannot get in from outside — not even with the right password.

When you have both, the device is offered first: it is one gesture instead of typing six digits.

Leaving the list empty is a valid choice

With no addresses set, SHTERA always asks for the second step, from anywhere. That is the safest option and it is the default.

What the list buys is not extra security but convenience in the place where you already are physically present — and a way back, which the next section explains.

It is also how you get back in

If you lose the phone with the app, or the computer that held your quick access, the list is the way out: you sign in from a trusted address with your password, and from inside you register another device or set up the app again.

That is why it is worth having at least one address on file even if you do not use it daily. With no list and no second factor, the only way out is to write to us.

Whole company, or one person

There are two levels. The account owner sets a list for the whole company: anyone without their own inherits it.

And they can give one person their own list, which replaces the company one. Useful to tie someone to the office without locking in everyone else — an administrator who should only connect from headquarters, say.

The same goes for AI agents: they are accounts like any other, and pinning their address is especially useful, because a stolen token works from anywhere and a fixed address anchors it to one specific server.

How to set it up

In the panel, "Addresses" section. At the top you see the address you are connecting from right now, so you do not have to guess it: if you want that one trusted, copy it exactly.

Write one per line or separated by commas. Only the account owner can set them: if everyone could edit their own, the person restricted to the office would lift the restriction themselves.

Every change is recorded in the audit log, with who made it and whose list changed.

Check it is a fixed address first

Most home connections have a dynamic address: it changes on its own every so often. If you set one that later changes, you are not locked out —you keep signing in with the second step— but the convenience quietly disappears.

If your office has a fixed address, that is the one to use. If you work through a corporate VPN, the VPN exit address also works and is usually fixed.