> ## Documentation Index
> Fetch the complete documentation index at: https://docs.praxis-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# More security for Canvas login

> Pria now confirms the identity of admin accounts with a one-time code when it opens inside Canvas. Who is asked, what the step looks like, and what to do if you get stuck.

Pria now asks **admin accounts** to confirm their identity with a one-time code when they sign in — including when Pria opens inside a Canvas page. **Students are not affected.** This page explains who sees the extra step, what it looks like, and what to do if something goes wrong.

## What changed

* **A second check for admin accounts.** Admins and account managers confirm it's really them with a short code before Pria lets them in. A stolen or guessed password is no longer enough.
* **Canvas can't sign an admin in silently.** When a Canvas page opens Pria for an admin account, Pria stops and asks for the code first.
* **Only the right people get admin rights.** A Digital Twin created from a Canvas course must be confirmed by its contact person (with an email code) before they can administer it. Organisation sign-in (SSO) only signs in people who are already members.
* **Sensible limits.** Codes expire quickly, wrong attempts are limited, and a trusted device stays trusted only on the network where it was verified.

## Who is asked for a code

| Account | Asked for a code? |
| - | - |
| **Students / learners** | **No.** Nothing changes for them. |
| **Admins, account managers, Digital Twin admins** | Yes, when their account has two-step verification turned on — by themselves in their profile, or by an admin under **Admin → Users** (the **Security** tab). |
| **Instructors listed as the contact of a Digital Twin** | Once — the first time they take an admin action from a Canvas course. |

You are **not** asked again when:

* you verified on this device in the last **24 hours inside Canvas** (7 days in a normal browser tab), on the same network; or
* your Digital Twin uses **Authenticate with Canvas** — the Canvas sign-in itself counts as the second check.

<Note>
  Switching to a new network (a different Wi-Fi, a VPN) means a new code, even on a trusted device.
</Note>

## What you will see in Canvas

<Steps>
  <Step title="Pria asks to confirm it's you">
    You open a Canvas page where Pria is embedded. Pria's panel shows **Confirm it's you** instead of the usual view — right there in the page. No new tab, no pop-up.
  </Step>

  <Step title="Send me a code">
    Click **Send me a code**. Pria emails a **6-digit code** to the address on your account. Nothing is sent until you click, so you won't get an email on every Canvas page.
  </Step>

  <Step title="Type the code">
    The code is valid for **5 minutes**. After **5 wrong tries** you'll need to request a new one (allow 30 seconds between requests).
  </Step>

  <Step title="Carry on">
    Pria continues where it left off, and remembers this device on this network for 24 hours.
  </Step>
</Steps>

If you set up an **authenticator app** in Pria, use its 6-digit code instead of email. Setting it up also gives you **10 single-use backup codes** — keep them somewhere safe.

<Tip>
  If the code screen has been open for more than about 10 minutes, Pria asks you to **reload the Canvas page** and start again. That's expected, not an error.
</Tip>

## If something goes wrong

<AccordionGroup>
  <Accordion title="&#x22;Account temporarily locked&#x22;" icon="lock">
    Too many wrong codes (10 in an hour, or 20 in a day). Wait the time shown, or ask an admin to clear it.
  </Accordion>

  <Accordion title="No access to your email, authenticator or backup codes" icon="envelope-open">
    An admin opens **Admin → Users**, edits your user and, on the **Security** tab, turns off **Require email MFA for this user**. That resets your second factor and trusted devices; your next sign-in goes straight through, and you can set two-step verification up again from your profile.
  </Accordion>

  <Accordion title="Asked for a code on every Canvas page" icon="browser">
    Your browser is blocking storage for embedded sites (private browsing, or strict cookie settings). Pria still works; allow site data for Pria, or use a normal window.
  </Accordion>
</AccordionGroup>

## Checklist for Digital Twin admins

* Tell your admins and account managers to expect the **Confirm it's you** step in Canvas, and to use the email address on their Pria account.
* If you want the code check for a specific admin, turn it on under **Admin → Users** (the **Security** tab).
* If your Digital Twin already requires **Authenticate with Canvas**, your admins will not see an extra prompt.

## Related

* [Multi-Factor Authentication (MFA)](/mdx/admin-guide/mfa) — managing two-step verification for your users
* [Access your LMS](/mdx/user-guide/lms/user-auth) — connecting Pria to your LMS account
* [Custom Theme](/mdx/integrations/canvas/theme) — how Pria is embedded in Canvas


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.