Password, email, two-factor authentication, sessions, and login history.
Manage authentication and session security from Settings → Security.
Overview
The Security page includes email change, password updates (non-OAuth accounts), two-factor authentication (2FA), active sessions, and login history (access logs). Workspace API keys are managed per property under Implementation.
Why it matters
Strong authentication protects consent records, billing data, and API keys. Session review helps you revoke compromised devices quickly.
Setup
Password and email
- Open Settings → Security.
- For email change, enter the new address and confirm via the inbox link.
- For password accounts, use Change Password with your current password.
OAuth-only accounts (Google/Microsoft) use the provider’s password reset flow.
Two-factor authentication (2FA)
- Click Enable 2FA.
- Scan the QR code with an authenticator app.
- Enter the 6-digit code to confirm.
- Store recovery codes when shown.
Sessions
Use Sign out others after travel or device loss. Revoke individual sessions from the list.
Examples
| Event | Where to look |
|---|---|
| Failed login spike | Login history on Security page |
| New device sign-in | Sessions list |
Troubleshooting
- 2FA code rejected — Sync device clock; use a fresh code.
- Email change stuck — Check pending inbox; link expires in 24h.
- Cannot disable 2FA — Requires current TOTP or recovery code.
Best practices
- Enable 2FA for all workspace owners and admins.
- Revoke unknown sessions immediately.
- OIDC SSO for Enterprise — contact sales for IdP onboarding (not self-serve in dashboard).
Related
- API setup — property API keys
- Workspace settings — team access