Account security
Manage sign-in methods, email verification, two-factor authentication, recovery codes, and sessions.
Open Account & security in the dashboard to manage your password, connected sign-in providers, two-factor authentication, and active sessions.
Sign-in methods
Use email and password or an enabled social provider shown on the sign-in screen. The Last used label under a social button is a convenience hint for that browser. It does not authenticate you or select an account automatically.
To add another social sign-in method to an existing account, first sign in using a method already connected to it, then connect the provider from your account security settings. Matching email addresses do not automatically merge unrelated accounts.
GitHub sign-in is separate from authorising the GitHub App to deploy repositories. See GitHub deployments.
Email verification
Verify your account email before accessing workspace operations. Under Account Settings → Email addresses, you can add an address, request another verification email, and make a verified address primary.
Check spelling and spam folders if mail does not arrive. Invitation acceptance requires a verified email matching the invitation, so verify the invited address rather than trying a different account.
Password recovery
Use Reset it on the login page if you cannot remember your password. Open the newest recovery email and complete the reset flow. Do not share a reset link with another person.
Security changes may require you to confirm your identity again. This protects sensitive actions even when a browser has an existing session.
Enable two-factor authentication
- Open Account & security and start authenticator setup.
- Scan the QR code with a TOTP authenticator app, or use the manual setup key.
- Enter a current code to confirm setup.
- Save the generated recovery codes somewhere secure and separate from the device.
Use a recovery code if the authenticator is unavailable. Each recovery code is intended for one use. Treat the setup key and recovery codes like passwords; do not include them in screenshots or support messages.
If codes are rejected, check the device's clock and time synchronisation, then enter a fresh code. Contact support if you have lost every valid recovery method; do not repeatedly create new accounts to try to recover a workspace.
Workspace enforcement
Workspace owners and admins with the relevant paid entitlement can require TOTP for members. Enable two-factor authentication on your own account before setting that requirement.
The requirement applies when accessing workspace resources, including API operations tied to a member. It does not replace the member's workspace role or API-key scope.
Review active sessions
Use the sessions list to inspect current sign-ins and revoke devices you no longer use. Sign out when finished on a shared device.
Revoking the browser session also ends dependent phpMyAdmin access on subsequent requests. Merely closing a browser tab is not the same as revoking a session.
Protect application credentials
Store application secrets in environment variables or secret files, and create separate API keys for separate automation purposes. Never put an Openstead API key into browser JavaScript.
If a secret is exposed, revoke or rotate it at its source and update the applications that use it. Removing a leaked value from Git's latest commit does not remove it from earlier history.