---
title: "Setting up an approval signing token"
canonical: "https://support.appfire.com/space/CDCCL/630986489/Setting%20up%20an%20approval%20signing%20token"
format: markdown
---
> Macro (aura-html)

## Overview

E-signatures for reviewers are required for approvals in the [Quality Management System workflow](https://appfire.atlassian.net/wiki/spaces/CDCCL/pages/631177774).

Setting up the approval signing token for the e-signature first time requires a few special steps

- adding an authentication app to your smart device
- [initializing the signing token](https://appfire.atlassian.net/wiki/spaces/CDCCL/pages/630986489/Setting+up+an+approval+signing+token#Initialize-Signing-Token%5BinlineExtension%5D) for the user for Comala Document Control approvals by adding a new authentication account to the app
- [generating a token](https://appfire.atlassian.net/wiki/spaces/CDCCL/pages/630986489/Setting+up+an+approval+signing+token#Adding-the-approval-signing-token-account-to-the-authenticator-app%5BinlineExtension%5D) from the linked authenticator app

## Add the authentication app to your smart device> Macro (anchor)



Download and install a 2 Factor Authentication (2FA) app through your device app store. Here are some possible examples:

- **Android**: [Authy](https://play.google.com/store/apps/details?id=com.authy.authy&hl=en_GB), [Google Authenticator](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en_GB), [1Password](https://play.google.com/store/apps/details?id=com.agilebits.onepassword&hl=en_GB)
- **iPhone**: [Authy](https://apps.apple.com/us/app/authy/id494168017), [Google Authenticator](https://apps.apple.com/gb/app/google-authenticator/id388497605), [1Password](https://apps.apple.com/us/app/1password-password-manager/id568903335)

<span style="color: #172b4d">You may already have an app installed if you have 2FA for other internet sites.</span>

> 📝 <span style="color: #172b4d">If you are already using 2FA for Confluence login, this is not the same. </span>

<span style="color: #172b4d">A new authentication account needs to be added to the app that is just used for Comala Document Control approvals.</span>

<span style="color: #172b4d">The first time a user is required to approve content in the QMS workflow, they aree required to initialize the signing token to create their authentication account in the authentication app.</span>

## <span style="color: #172b4d">Initialize Signing Token</span>

<span style="color: #172b4d">The very first time a user is expected to approve a page, they are asked to set up a personal code.</span>

![image](media://38ad216f-26a5-49db-bba5-cbe76f02a6cf)

Choose **setup personal code**.> Macro (anchor)



The two-step setup process is shown.

![image](media://7ef5f35c-caf9-4d58-8ce0-6e1536394d76)

You must first download and install the 2FA app on your smart device.

- the approval signing token is generated using one of several different apps such as<span style="color: #172b4d"> Google Authenticator available from Google Play and Apple App Store</span>
- <span style="color: #172b4d">the authentication client must be installed and linked to your email for the Confluence instance</span>

Once the 2FA app is installed on your device

- add your email address to Step 2 in **Comala Document Control signing token setup** dialogue box
- choose **Validate** to generate a confirmation email with a link that allows you to set up the authentication app installed on your device

There is an option to resend this email if required.

![image](media://15ee3141-e64c-420d-b4ef-aea11eeedf11)

<span style="color: #172b4d">To validate your email address c</span>hoose the **Go to approval signing token settings** link in the email.

![cdcc_email_notifcation_esignaturesetup.png](media://e8b37578-03f5-49a7-b4f9-6fa107623893)

> ℹ️ The link for the email validation is time-limited to 15 minutes. After this period a new validation email is required.

The link returns you to the instance. A QR code is displayed to use for the signing token setup using the authenticator app installed on your smart device.

![image](media://ac41ccb4-cb85-4679-9f83-fa13aa83ae50)

- use of this QRCode or key is time-limited to 30 minutes
- a key is also shown for the manual set up of the authenticator app

To initialize the approval signing token, the QRCode must be scanned to your smart device authenticator app. This will generate an authentication account specific to the user email and Comala Documentation Control.

## Adding the approval signing token account to the authenticator app> Macro (anchor)



The QR code will be used by the authenticator app to set up the authentication account linked to the user and the Confluence instance.

A numeric signing token will be generated by your authentication app using the QRCode. This signing token is specific to the content review and will be different to any 2FA token you may use for access to your Confluence instance.

Scan the QRCode generated to your authenticator app.

![image](media://30bb4db7-b746-43ac-9429-b6b0b79bd834)

Choose the account details (such as logo or name, if appropriate).

![image](media://f6eb16ae-35d9-4e9a-93ec-07fe40321671)

Choose **Save**.

![image](media://d37324da-5dc5-419f-8620-5c35538546df)

- note the six-figure numeric signing token
- the approval signing token is renewed every 30 seconds by the authenticator app

Add the approval signing token to the **Comala Document signing token setup** dialogue box.

![image](media://db863733-3ac3-4976-a840-67a5809b1f61)

Choose **Validate**.

![image](media://df9e80b6-ede3-45ee-a3ef-0a6d6148ea11)

- signing token creation date for the setup and the expiry date are displayed
- Confluence administrators can reset the need to initialize the signing token

## Setting up approval signing token through the workflow report

An individual user can set up the signing token through the **Document Report**.

Select **Document Report** in the sidebar.

![image](media://adf54b44-d721-496f-8485-cfc33b9c5d16)

Choose the** E-signature token setup** link.

![image](media://dfc27bba-d49a-481b-9b94-e2efe840d9b4)

If the signing token setup is complete and valid, the link displays confirmation.

![image](media://1e03cf37-f13e-41ce-8442-f0960cfb5557)

If there is no valid token setup, the link displays the signing token setup dialogue box. 

> ℹ️ Once set up for a user, new numeric signing tokens are generated every 30 seconds by the authentication app.

With e-signature set up, when the user undertakes an approval

- the numeric signing token displayed by the authentication app is required to activate the content review
- the e-signature credentials are checked when the approve or reject decision is made

Navigating away from the popup and returning later may require a new 6-figure numeric token generated by the authentication app.

## Using an approval signing token to activate the review

In the content review workflow popup add your email address and the current authenticator app generated signing token displayed on your smart device.

![cdcc_approvalpopup_esignature_email_token_elle.png](media://8852e4fd-af3b-44a5-8c06-e7a0073b75e1)

If the signing token and email are accepted, the popup content review buttons become active for that user.

The content review for the **In Approval** state also requires an e-signature.

![image](media://71480853-5498-4d55-a33e-f8e6aebb6390)

If the current user has already set up a signing token there is no prompt in the workflow popup. The approval buttons are simply disabled until the email and a token are added.

> 📝 A different approval signing token generated by the authenticator may be required for the same user if more than one minute has elapsed since the use of any previous token.

When a valid signing token and email address are added, the review buttons are activated.

![cdcc_qms_inapproval_esign_elle.png](media://fa94ba3c-3cb9-4e44-9d7c-df3cb2e8add3)

## Multiple reviewers

Where there are multiple reviewers, a separate approval signing token will be required by each reviewer

- <span style="color: #172b4d">for usability, user validation is provided against previous, current, and the next calculated signing tokens generated by the authenticator app</span>
- the e-signature process submits the user email address and approval signing token through the Appfire Comala secure server without storing these details

> 📝 E-signature does not work if your site is configured to use single sign-on (SSO).

## Approval signing token admin

Administrators can view all setup tokens for users in the instance.

![image](media://6880bcf7-c9a4-468f-ae84-79b2578b3a1c)

A global administrator can

- remove the signing token for users, requiring users to re-authenticate with the app
- set a signing token expiry date for a user

## Related Links

- [E-signatures](https://appfire.atlassian.net/wiki/spaces/CDCCL/pages/630985848)
- [Using a signing token to activate a review](https://appfire.atlassian.net/wiki/spaces/CDCCL/pages/630952432)
- [Quality Management System Workflow](https://appfire.atlassian.net/wiki/spaces/CDCCL/pages/631177774)