Faelith
ContactDownload
Account security

Account

Account security

Email verification, two-factor authentication, confirmations and recovery.

Sign-up#

New accounts confirm their email with a 6-digit code before the account is created. You can also sign in with GitHub or Google; only provider-verified emails are accepted, and a provider is never linked automatically to an account that has a password — sign in with your password and link it from Settings.

Two-factor authentication#

Turn it on under Settings → Security. Every sign-in, including GitHub and Google, then asks for a second factor:

  • Authenticator app — scan the QR code with any TOTP app.
  • Email code — a 6-digit code sent to your inbox.
  • Backup codes — 12 single-use codes shown once when you enable 2FA. Store them safely; you can regenerate them.

With an authenticator app enabled, an email code is not accepted to change or disable your factors.

Confirming sensitive actions#

Creating API keys, changing your password, unlinking a provider, enabling usage-based billing, approving a device login and deleting your account ask you to confirm it is you (a 2FA code, or your password when 2FA is off). You receive an email whenever one of these happens.

Device logins#

When the CLI or desktop app signs in through the browser, the approval page shows the IP address, client and time of the request. Approve it only if you started it yourself.

Forgot your password#

Use Forgot your password? on the sign-in page. The link works once, expires in 30 minutes and signs out every session; two-factor authentication still applies at the next sign-in.

Deleting your account#

Settings → Delete account revokes every API key, cancels your subscription and removes your data, including the encrypted model-I/O capture.

Found a mistake or a gap? Tell us and we will fix the page.