# Account security

> Two-factor authentication, password rules, sign-in lockout, changing and resetting your password.

Source: https://managerunners.com/docs/manual/account-security/

## Two-factor authentication

Every account uses two-factor authentication (2FA) with an authenticator app (TOTP). You set it up during registration by scanning a QR code, and you enter a 6-digit code from the app every time you sign in to the dashboard.

There are no recovery codes, and 2FA cannot be turned off. Keep your authenticator app backed up. If you lose access to it, contact [support@managerunners.com](mailto:support@managerunners.com).

The CLI asks for a 2FA code when it logs in with your password. Personal access tokens do not need 2FA, which is why they are limited by [scopes and an expiry](https://managerunners.com/docs/manual/access-tokens/).

## Passwords

A password needs at least 8 characters, including an uppercase letter, a lowercase letter, a number and a symbol.

### Change your password

1. Open **Settings** and go to **Security Settings**.
2. Enter your current password and the new password twice, then select **Continue**.
3. Enter a 6-digit code from your authenticator app and select **Verify & Change**.

### Reset a forgotten password

1. On the sign-in page, select **Forgot password?**.
2. Enter your email address and select **Send reset link**. For privacy, the page shows the same message whether or not an account exists for that address.
3. Open the link in the email within 15 minutes, choose a new password and select **Update password**.

Only the most recent reset link works. Resetting your password does not change your 2FA setup: you still sign in with your authenticator app.

## Sign-in lockout

After a failed sign-in, the account is locked for a short time, and each further failure makes the lock longer. The sign-in page shows how long to wait. A successful sign-in or a password reset clears the lock.

## Sessions

A dashboard session lasts up to 8 hours. Signing out ends it. Your name and email address cannot be changed in the dashboard.
