Security
Open Account → Security to manage passwords, authenticators, passkeys, and recovery codes. These settings apply across Workspaces.
For personal details and verified contact methods, see Profile. To inspect actions available to your account, see Activity.
Login Methods
Use the sign-in methods offered on your login page. A magic link or SMS code is sent to the matching contact method; keep the message private and complete its verification prompt. If an email link expires, request another from the login page.
Email & Password
To set or change your password, open Account → Security and use the password card. When changing an existing password, enter your current password and confirm the new one. Follow any additional verification prompt, then check the success message before closing the form.
Passwords must contain 12–72 characters. No uppercase, lowercase, digit, or special-character combination is required. A password found in known breach records is rejected; choose a different password if the form reports that result.
Two-Factor Authentication (2FA)
The Security tab shows whether two-factor authentication is enabled and lists its Configured Methods. Set up a method you can use on the devices where you sign in, then confirm that it appears in this list.
Authenticator App Setup
- Under Add New Method, choose Set Up Authenticator App.
- Give the authenticator a recognizable name and choose Continue.
- Scan the displayed QR code in your authenticator app, or use the manual entry key when scanning is unavailable.
- Continue to verification and enter the current six-digit code from the app.
- After verification succeeds, check Configured Methods for the named authenticator and the enabled status above it.
The QR code and manual key configure your sign-in factor. Keep them private. Next, generate recovery codes so losing the authenticator does not leave you without that recovery method.
Set Up a Passkey
- In Security → Add New Method, choose Set Up Passkey.
- Name the passkey and continue to Register Your Passkey.
- Choose Register Passkey and complete your browser or device's prompt for biometrics or a physical security key.
- Return to Configured Methods and confirm that the named passkey appears.
If you cancel the device prompt, registration has not completed. Retry from the setup dialog instead of assuming the passkey was saved.
Recovery Codes
- In the Recovery Codes card, choose Generate Recovery Codes, or Regenerate Recovery Codes when you already have unused codes.
- Read the replacement warning before generating a new set. Regeneration invalidates the previous codes.
- Download the displayed codes or record them in a secure location you can reach without the authenticator device. Treat them as sign-in credentials.
- Complete the dialog's acknowledgement after saving them. Confirm that you can retrieve your saved copy before closing the dialog.
Each recovery code can be used only once. When a sign-in challenge offers Recovery Code, use an unused code from your saved set. Do not send the codes to colleagues or include them in support requests.
Logging In with 2FA
Complete the sign-in challenge using an available configured method. If your usual device is unavailable, use the offered recovery-code option. The Security page lists configured methods and their last-used time when available; those entries let you check which methods remain attached to your account.
Session Management
To sign out on your current device, open the account menu and choose Log Out. This action does not claim to revoke every other device's session. Check your configured sign-in methods in Security when reviewing account access.