---
title: "Set up an approval signing token"
canonical: "https://support.appfire.com/space/CDMC/2193853885/Set%20up%20an%20approval%20signing%20token"
format: markdown
---
## Overview

When e-signature is enabled for the workflow, a reviewer needs to authenticate their identity using a third-party app. Setting up authentication for the first time requires a few special steps. 

- **Add an authentication app** to your smart device
- **Initialize the signing token** for the user for Comala Document Management approvals by adding a new authentication account to the app
- **Generate a token** from the linked authenticator app

The e-signature process submits the email address and approval signing token through the Comala secure server without storing these details.

> 📝 The e-signature does not work if your site is configured to use single sign-on (SSO) through Atlassian Access.

## Add the authentication app to your smart device

Download and install a two-factor authentication (2FA) app through your device's app store. Here are some possible examples:

- **Android**: [Authy](https://play.google.com/store/apps/details?id=com.authy.authy&hl=en_GB), [Google Authenticator](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en_GB), [1Password](https://play.google.com/store/apps/details?id=com.agilebits.onepassword&hl=en_GB), [Microsoft Authenticator](https://apps.apple.com/gb/app/microsoft-authenticator/id983156458)
- **iPhone**: [Authy](https://apps.apple.com/us/app/authy/id494168017), [Google Authenticator](https://apps.apple.com/gb/app/google-authenticator/id388497605), [1Password](https://apps.apple.com/us/app/1password-password-manager/id568903335), [Microsoft Authenticator](https://apps.apple.com/gb/app/microsoft-authenticator/id983156458)

If you are already using 2FA for Confluence login, this is not the same. 

A new authentication account needs to be added to the app that is just used for Comala Document Management approvals.

For example, the first time a user is required to approve content in the included Quality Management System workflow, they are required to initialize the signing token to create their authentication account in the authentication app.

## Initial signing token setup

The first time a reviewer is required to undertake an approval requiring identity authentication, they must set up a personal code.

To set up a personal code,

1. Click the **setup a personal code** link in your workflow state dialog box.

![Comala workflow dialog with approval authentication setup in review state](media://e39bd4ab-ebe1-46e5-8711-14e0200b5d5c)

2. The two-step setup process is shown. Enter your email address and click **Validate.**

![Comala signing token setup dialog](media://8e03dc4e-e655-4fac-b472-997c6d388ae9)

> ℹ️ There is an option to resend this email if required.
> ℹ️ 
> ℹ️ ![Comala signing token email entry field](media://c37bc774-e8c0-4685-81bf-210298ddf8fb)

3. You will receive an email from Comala Document Management to set up your approval signing token. Open the email, validate your email address, and click the **Go to approval signing token settings** link to complete the setup.

![Comala approval sign token email validation with link to settings](media://3aba640f-a573-4f10-a22d-36eb56a1e7eb)

> 📝 The link for the email validation is time-limited to 15 minutes. After this period, a new validation email must be requested.

4. The link returns you to the instance. A QR code is displayed to set up the signing token using the authenticator app installed on your smart device. The QR code or key is valid for 30 minutes.

![Comala signing token with QR code for authenticator app](media://64526290-2912-47e8-8ab5-8ed735ed68c3)


5. To set up your approval signing token, scan the QR code using a mobile phone authenticator app. This creates an authentication account linked to your email and Comala Document Management. A manual setup key is also provided if you can’t scan the QR code.

## Add the approval signing token account to the authenticator app

Scan the QR code with your authenticator app to set up an authentication account linked to your user and Confluence instance.

The app will generate a numeric signing token used for approval. This token is specific to the approval process and is **not** the same as any 2FA token used to log in to Confluence.

![Comala authenticator app add account screen](media://7047c66e-9356-4104-828c-5b05a03e27f1)

1. Choose the account details (the logo or name, if appropriate).

![Comala authenticator app with account added](media://19d2030b-4e75-48df-842c-fb8570acc4ea)

2. Click **Save**.

![Comala authentication token code displayed on phone](media://4ede78b1-c105-4b28-af51-35158ceea629)

3. Note the six-figure numeric signing token. The approval signing token is renewed every 30 seconds by the authenticator app
4. Add the approval signing token to the **Comala Document Management signing token setup** dialogue box.

![Comala signing token setup dialog with verification code entry](media://3a365a28-a7e9-44a0-8b52-bfaa0626295e)

5. Click **Validate.**

![Comala authentication token validation success message](media://f14e1ca6-b4df-4800-8463-f4adbfd452a9)

> ℹ️ The signing token’s creation date and expiry date are displayed during setup.
> ℹ️ 
> ℹ️ Confluence administrators can reset the token setup if needed.

## Set up the approval signing token through the document report

An individual user can set up the signing token through the **Document Report**.

Select **Document Report** in the sidebar.

![Comala document report navigation link in sidebar](media://17a6098c-787d-49ee-bce4-672d9d40f2e2)

Choose the** E-signature token setup** link.

![Comala document report with signing token audit entries](media://92662059-be82-4c44-8ab5-30cd32bdfc92)

If the signing token setup is complete and valid, the “**Comala Document Management signing token setup is complete!”** screen is displayed.

If no valid token is set up, the link displays the signing token setup dialog box. 

## Use an approval signing token to activate a review

The approve and reject buttons in the workflow state dialog box are disabled when user authentication is required for an approval.

You must use the approval signing token to activate the approval buttons by adding:

- Your email address
- The numeric signing token in the state dialog box

![Comala approval popup with esignature email token entry](media://160bb7b2-b98d-41bd-bf92-7bb1d58eb243)

> ℹ️ The token validity is checked when the decision to **approve** or **reject** is made.

Navigating away from the state dialog box and returning later can require a new numeric token.

## Global administration of tokens

Global administrators can view all setup tokens for users in the instance in the app's global **Signing Token Admin** screen.

![Comala global signing token admin with remove and set expiry options](media://5a481854-1d74-41e6-8641-5625d278383e)

Global administrator can:

- **Remove a user’s signing token**, requiring them to re-authenticate
- **Set an expiry date** for each signing token

**Authentication apps**

- [Authy](https://play.google.com/store/apps/details?id=com.authy.authy&hl=en_GB)
- [Google Authenticator](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en_GB)
- [1Password](https://play.google.com/store/apps/details?id=com.agilebits.onepassword&hl=en_GB)
- [Microsoft Authenticator](https://apps.apple.com/gb/app/microsoft-authenticator/id983156458)