Securing your account
Turning on two-factor authentication, keeping recovery codes, ending browser sessions and revoking credentials, and what the step-up check is for.
Updated
The security page is about your own account rather than your organisation. Every signed-in person has one and needs no particular role.
Four things live here: two-factor authentication with recovery codes, the step-up check that sensitive actions ask for, the browser sessions you are signed in on, and the credentials connected to your account.
BEFORE YOU START
- An authenticator application on your phone, if you are turning on two-factor authentication.
- Somewhere safe to keep recovery codes. They are shown once.
- A few minutes. Turning two-factor off, regenerating codes and signing out other sessions all ask for a fresh check first.
STEPS
- Open Security, or go to /app/security.
- Choose to enrol in two-factor authentication. Scan the code shown on the page with your authenticator, or copy the secret into it.
- Enter a code from the authenticator to confirm. Two-factor is not on until you do.
- Save the recovery codes. Each works once if you lose the authenticator.
- Review the browser sessions: what device, what address, when it was last active, and which one is this device. Revoke any you do not recognise.
- Review the connected credentials and revoke any you no longer use. Mobile sign-ins appear here.
- Use "Sign out all other sessions" if you think something is wrong.
WHAT YOU SHOULD SEE
Two-factor shown as enabled with a count of unused recovery codes, and lists of sessions and credentials you can act on individually.
WHAT THIS WILL NOT DO
- It will not offer an address allowlist. There is no such feature in this product.
- It will not set up single sign-on. Sign-on connections and directory provisioning are configured per organisation by support staff, not from this page. Where your plan includes them, your team page explains that saving the details does not switch them on: a connection has to pass verification and then be enabled explicitly.
- It will not change a password. Identity is federated in this product.
- It will not enrol two-factor from your phone. The mobile screen reads your settings and revokes sessions and tokens, and says to turn two-factor on from the web app.
WORTH KNOWING
Some actions elsewhere in the product ask for a step-up: minting an API token, minting an assistant token, and the security changes above. Step-up means proving it is you again, recently, with your authenticator, your identity provider, or a fresh identity token. An account with no factor at all has no step-up method, and enrolling two-factor is the way to gain one.
IF IT DOES NOT WORK
- "That code is not valid." means the authenticator code was wrong or has already rolled over.
- "This action needs a fresh security check." is the step-up prompt appearing where you did not expect it. Enter a code and continue.
- "No step-up method is available on this account. Set up two-factor authentication to gain one."
- "This account signs in through an identity provider. Re-authenticate there to step up."
- "That session cannot be revoked." usually means it is the session you are using.
- "That token does not exist." means it was already revoked.
- On mobile, "The request did not complete, so it is not known whether that was revoked. Reload to check." means exactly that.
COMMON QUESTIONS
I have lost my authenticator. What now?
Use a recovery code. Each works once. Then regenerate a fresh set and enrol a new authenticator.
Does revoking a credential sign me out of the mobile app?
If the credential you revoke is that device's, yes.
RELATED GUIDES
- Reading the audit trail
Who did what and when across the organisation, the separate trail of your own account security events, and the two things deliberately left out of both.
- Using the developer API
Minting an API token with read and write scopes, what the ninety-day lifetime means, where the OpenAPI contract lives, and what the request log does and does not record.
- Inviting your team
Creating an invitation link, choosing from the fourteen roles and what each one can do, how seats are counted, and what the team page cannot do.