Password and 2FA
Changing your password, two-factor authentication and active sessions
Changing your password
- Open Account and click "Change password" in the header of the "Password" card.
- Fill in "Current password *", "New password *" and "Confirm password *". The "Password requirements" list is highlighted as you type.
- Click "Change password".
After a password change, an email with a cancellation link is sent to you: if it was not you who changed the password, follow the link and the change will be reverted. All other devices are signed out of the account at that point — signing in from them again will require the new password; the current device stays signed in. The list of sign-ins and forced sign-out are in the "Active sessions" card on the same page. We recommend changing your password every three months and not reusing it on other sites.
Two-factor authentication (2FA)
With 2FA enabled, every sign-in requires a one-time 6-digit code in addition to your password. Without it, a single password is all an attacker needs.
- In the "Two-factor authentication" card, click "Enable" — the "2FA setup" window opens.
- Scan the QR code with an authenticator app (Google Authenticator, 1Password, etc.) and click "Next".
- Enter the 6-digit code from the app and click "Confirm".
- Save your backup codes and confirm this with the "I saved the codes" button — they let you sign in if you lose access to the app.
- At sign-in you can enter a code from the app, switch to a backup code, or — under the "Get the code another way" heading — request a code in Telegram with the "📱 via Telegram" button or by email with the "✉️ by email" button.
- Disabling 2FA takes two steps: first your account password, then a code the service sends on its own — to Telegram if the bot is linked, otherwise by email. The code is valid for 5 minutes; codes from the authenticator app and backup codes are not accepted at this step.
- You get 3 attempts to disable it: a wrong password and a wrong code are counted together. After the third error, disabling is temporarily blocked and the code has to be requested again.
Store your backup codes in a safe place. Each code can be used only once.
Active sessions
The "Active sessions" card on the Account page shows the devices the account is open on. The card header has a "Devices: N" counter.
- Each row shows the device (browser and its type), the IP address, and the city and provider when they are known.
- "Signed in" — when the session was created; "Activity" — when it last accessed the service.
- The session you are reading this page from is marked "Current".
- The "End" button in a row disconnects one device; "End all other sessions" in the header disconnects every device except the current one (the button appears only when there is at least one other session).
- Both actions ask for confirmation — in the "End this session?" or "End all other sessions?" window.
- Signing in from a disconnected device again will require the password.
If you end the current session, you will be signed out of the account on this device — the confirmation window warns about this as well.