Account security

Account security

Two-step verification (2FA)

Add a second factor from Settings → Two-Step Verification:

  1. Tap Set up — scan the QR with any authenticator app (Google Authenticator, Authy, 1Password…), or enter the key manually.
  2. Confirm with a 6-digit code.
  3. Save your backup codes. Ten one-time codes, shown exactly once, stored hashed on our side.

With 2FA on, signing in requires a current authenticator code (or an unused backup code). Turning 2FA off also requires a valid code — a walk-up attacker with your unlocked screen can't strip your protection.

Passkeys

Passkeys sign you in with your device's biometrics/PIN — phishing-resistant and password-free. Register them from Settings → Passkeys. A passkey sign-in already proves device possession, so it satisfies two-step verification inherently: no extra code prompt.

Linked Devices

Settings → Linked Devices shows every active session:

  • Device and browser, sign-in time, and approximate location (with a map preview).
  • Your current session is labeled.
  • Sign out any single session, or everything except this one.

Revocation is immediate: the session's realtime connections are cut the moment you revoke — not on its next refresh.

Recovery

  • Lost authenticator → use a backup code, then re-enroll.
  • Forgotten password → Forgot password sends a reset code to your email.
  • Regenerating backup codes invalidates all previous ones.