Account security
Account security
Two-step verification (2FA)
Add a second factor from Settings → Two-Step Verification:
- Tap Set up — scan the QR with any authenticator app (Google Authenticator, Authy, 1Password…), or enter the key manually.
- Confirm with a 6-digit code.
- Save your backup codes. Ten one-time codes, shown exactly once, stored hashed on our side.
With 2FA on, signing in requires a current authenticator code (or an unused backup code). Turning 2FA off also requires a valid code — a walk-up attacker with your unlocked screen can't strip your protection.
Passkeys
Passkeys sign you in with your device's biometrics/PIN — phishing-resistant and password-free. Register them from Settings → Passkeys. A passkey sign-in already proves device possession, so it satisfies two-step verification inherently: no extra code prompt.
Linked Devices
Settings → Linked Devices shows every active session:
- Device and browser, sign-in time, and approximate location (with a map preview).
- Your current session is labeled.
- Sign out any single session, or everything except this one.
Revocation is immediate: the session's realtime connections are cut the moment you revoke — not on its next refresh.
Recovery
- Lost authenticator → use a backup code, then re-enroll.
- Forgotten password → Forgot password sends a reset code to your email.
- Regenerating backup codes invalidates all previous ones.