Account security
Two-factor authentication, password rules, sign-in lockout, changing and resetting your password.
Two-factor authentication
Every account uses two-factor authentication (2FA) with an authenticator app (TOTP). You set it up during registration by scanning a QR code, and you enter a 6-digit code from the app every time you sign in to the dashboard.
There are no recovery codes, and 2FA cannot be turned off. Keep your authenticator app backed up. If you lose access to it, contact [email protected].
The CLI asks for a 2FA code when it logs in with your password. Personal access tokens do not need 2FA, which is why they are limited by scopes and an expiry.
Passwords
A password needs at least 8 characters, including an uppercase letter, a lowercase letter, a number and a symbol.
Change your password
- Open Settings and go to Security Settings.
- Enter your current password and the new password twice, then select Continue.
- Enter a 6-digit code from your authenticator app and select Verify & Change.
Reset a forgotten password
- On the sign-in page, select Forgot password?.
- Enter your email address and select Send reset link. For privacy, the page shows the same message whether or not an account exists for that address.
- Open the link in the email within 15 minutes, choose a new password and select Update password.
Only the most recent reset link works. Resetting your password does not change your 2FA setup: you still sign in with your authenticator app.
Sign-in lockout
After a failed sign-in, the account is locked for a short time, and each further failure makes the lock longer. The sign-in page shows how long to wait. A successful sign-in or a password reset clears the lock.
Sessions
A dashboard session lasts up to 8 hours. Signing out ends it. Your name and email address cannot be changed in the dashboard.
