Help

Security All help

Security

Every sign-in ends with a second factor, whether you came in with Google or a sign-in link. This page holds yours.

Credentials

Two kinds, and you name each one so you know which is which later:

  • Passkey โ€” Touch ID, Windows Hello, or a security key such as a YubiKey. One tap at sign-in, no code. Your browser creates it and it never leaves the device or key.
  • Authenticator app โ€” a 6-digit code from Google Authenticator, 1Password, Authy or any TOTP app. Scan the QR code (or type the key), then enter the code once to prove it works.

+ Add credential to add either kind; Rename and Remove on each row. Keep at least one โ€” Remove is disabled on the last. Adding a passkey on each device you use is the convenient setup; keep an authenticator or a security key as the fallback.

Recovery codes

Ten single-use codes that stand in for a passkey or authenticator code when you have none at hand. They're shown once, when generated; Generate new codes replaces the set. Used codes are struck through.

Lost everything?

An administrator can Reset access on your row under Users: your credentials and recovery codes are removed, your sessions end, any sign-in lock is cleared, and your next sign-in sets up a new second factor.

Every credential added, renamed or removed, and every reset, is recorded in Audit.