How do I log into the Chrome extension securely and via my SSO?
Instead of typing your password into the extension, you authenticate yourself on the web application (secure environment) and use a temporary code to link the extension to your account.
Step by step
- On the Chrome extension → Click on"Connect via device pairing".
- Automatic redirection → You are redirected to the web application
- Authentication → Log in with your usual credentials (SSO or classic)
- Pairing page → Once logged in, you're taken to the extension connection page
- Code generation → Click on "Generate a pairing code".
- A 6-digit code appears → Copy it (it expires in 3 minutes)
- Back to the extension → Paste the code into the Chrome extension
- Automatic connection → Your extension is now connected to your account
Durations and limitations
Temporary codes
- Lifetime: 3 minutes maximum
- Format: 6 digits (e.g. 123 456)
- Single use: Code is destroyed after use
- Only one active code: Generating anew code cancels the old one
Attempt limitation (anti-hacking security)
- Maximum 3 attempts per IP address
- If exceeded : 5-minute lockout
- Automatic reset: after 5 minutes of inactivity
Security features
Data protection
- No password storage in the extension
- Encrypted codes in database (unreadable even by administrators)
- Anonymized logs: compliance with confidentiality regulations
- Active monitoring: automatic detection of hacking attempts
Protection against attacks
- Rate limiting: impossible to "guess" a code by brute force
- Random codes: 1 chance in 1 million of finding the right one
- Short duration: very limited attack window (3 minutes)
- Automatic alerts: administrators are notified of suspicious activity
Benefits
For the user
- More secure: no password in the extension
- Simpler: no need to retype login details
- Total control: you can disconnect the extension at any time
- Familiar: same principle as Google Authenticator or SMS validation codes
For security
- Enterprise standard: used by major corporations
- Traceability: all accesses are logged
- Revocation possible: disconnect remotely if necessary
Special situations
If code expires
- Solution: Simply generate a new code
- Why: Enhanced security with short-term codes
If you have too many errors
- Message: "Too many attempts, please wait".
- Solution: Wait 5 minutes then try again
- Why: Protection against hacking attempts
If the extension disconnects
- Solution: Repeat pairing procedure
- Normal frequency: Automatic disconnection after session expiry
Troubleshooting
Common problems
Code not working :
- Check that it has not expired (3 minutes)
- Be sure to copy all 6 digits
- Generate a new code if necessary
Too many attempts" message:
- Wait 5 full minutes
- Do not attempt to generate new codes during this time
- Contact support if the problem persists
Redirection not working :
- Check that you are not in private browsing mode
- Temporarily disable ad blockers
- Allow pop-ups for the domain
Note: This connection method complies with the strictest security standards and effectively protects your personal data.