Skip to content

Multi-factor authentication for web logins

Starting September 1, 2026, signing in to LIGO.ORG web services in a browser also requires Duo, alongside your username and password. This is a separate sign-in check from SSH, but it's the same Duo account and the same devices — if you've already enrolled a device for SSH, you're already enrolled for web too, and there's nothing further to do.

There's a dedicated site for checking your status, registering, and managing devices: lvk-duo-registration.ligo.org.

Only two pages on that site are password-only

Everywhere on lvk-duo-registration.ligo.org — including the bare address — asks for password and Duo immediately. If you have no device registered yet, Duo puts you straight into its own enrollment screen at that point.

/registration and /description are the two deliberate exceptions: password only, so you can check your status or preview the flow before being forced into a Duo prompt.

Checking your status and registering

  1. Go to https://lvk-duo-registration.ligo.org/registration and sign in with your usual LIGO.ORG username and password. This specific address doesn't trigger a Duo prompt — it just tells you where you stand.

    LVK Identity landing page with the /registration link highlighted

  2. If it says "Register your second factor," click Register with Duo.

    Duo status page in the not-registered state

    That sends you to the site root, which requires Duo. Because you have no device yet, Duo puts you straight into its own enrollment screen — choose a method (phone push, or a hardware token) and follow Duo's prompts to finish. Unlike SSH, Touch ID and Windows Hello work here too — see the SSH vs. web comparison.

    Duo Mobile app OS requirements

    The Duo Mobile app requires Android 12+ or iOS 17+. If your phone is stuck on an older OS (for example, an Android 11 device that can no longer update), Duo Mobile may fail to install or update — use a hardware token instead.

  3. Once you've finished enrollment, visit /registration again — you should now see "You're all set."

    Duo status page in the enrolled state

For a fuller, screenshotted walkthrough of every step above (including trying Duo early and managing devices), see https://lvk-duo-registration.ligo.org/description.

Trying Duo early (optional)

If you're already registered and want Duo turned on for your own web logins before September 1, go to https://lvk-duo-registration.ligo.org/optin (password + Duo — you'll get a prompt using the device you already registered) and click Opt in to Duo web login.

Try Duo web login page in the not-opted-in state

From your next fresh sign-in, LIGO.ORG web services will ask for Duo — the same prompt everyone gets once it's required. You can opt back out from the same page any time before September 1.

Try Duo web login page in the opted-in state

August-only

Early opt-in is only available during the August registration window. On September 1, Duo becomes required for everyone regardless.

Managing your devices later

Once you're enrolled, /registration shows an Add or change a device button instead of the registration one.

Duo status page in the enrolled state with the device-management button highlighted

Clicking it forces a fresh Duo prompt (even if you signed in recently), so you can reach Manage devices — see Managing your devices for the actual self-service screens, which are identical whether you got there via SSH or web. Afterwards, you land back on a short confirmation page:

Duo devices confirmation page

Next steps