Security
Every sign-in ends with a second factor, whether you came in with Google or a sign-in link. This page holds yours.
Credentials
Two kinds, and you name each one so you know which is which later:
- Passkey โ Touch ID, Windows Hello, or a security key such as a YubiKey. One tap at sign-in, no code. Your browser creates it and it never leaves the device or key.
- Authenticator app โ a 6-digit code from Google Authenticator, 1Password, Authy or any TOTP app. Scan the QR code (or type the key), then enter the code once to prove it works.
+ Add credential to add either kind; Rename and Remove on each row. Keep at least one โ Remove is disabled on the last. Adding a passkey on each device you use is the convenient setup; keep an authenticator or a security key as the fallback.
Recovery codes
Ten single-use codes that stand in for a passkey or authenticator code when you have none at hand. They're shown once, when generated; Generate new codes replaces the set. Used codes are struck through.
Lost everything?
An administrator can Reset access on your row under Users: your credentials and recovery codes are removed, your sessions end, any sign-in lock is cleared, and your next sign-in sets up a new second factor.
Every credential added, renamed or removed, and every reset, is recorded in Audit.