Account & security
Account security
Email verification, two-factor options, trusted devices, and recovery.
- Email verification
- Required at signup; unverified accounts cannot sign in.
- Two-factor by default
- New accounts start with email sign-in codes as a second factor: every login asks for a one-time code sent to your inbox.
- Authenticator app
- Upgrade to TOTP in account settings under Security: scan the QR code, confirm a code, and store the one-time backup codes. The authenticator then replaces email codes.
- Trusted devices
- Tick "Trust this device" at sign-in to skip the second factor on that device for 30 days.
- Turning two-factor off
- You can remove the authenticator (falling back to email codes) or disable two-factor entirely; both require your password. Password-only sign-in is your call to make.
Forgot your password? The reset link is emailed and expires quickly. Backup codes each work exactly once; regenerate them by re-running the authenticator setup.