Skip to content

Password and 2FA

Settings → Security. Three cards, in the order of what they protect: the password that opens the account, the second factor that stands behind it, and the list of devices currently signed in.

The three fields are the current password, the new one, and a confirmation. A new password is at least 12 characters and at most 200; every character is accepted, and no composition rule asks for a digit or a symbol.

Length alone is not the whole bar. The API scores the password and refuses one that is guessable even when it is long enough, naming the part that gives it away: a common word, a keyboard walk, a date, a repeated fragment. motdepasse12345 is fifteen characters and is turned down.

Changing the password revokes every other session, on every device, and keeps the one you are using. That is the fastest way to end a session you are not sure about.

A second factor is a six-digit code from an authenticator app, asked for after the password at every sign-in. It is off until you turn it on.

  1. Press Enable. A QR code appears, with the same key printed as text underneath for an app that cannot scan.

  2. Scan it, then type the current six-digit code into the field and confirm. The code is checked before anything is turned on, so a mis-scanned QR fails here rather than at your next sign-in.

  3. Ten recovery codes appear, in the shape abcd-2345. Copy them, or download them as badlen-codes-recuperation.txt. The button that closes the panel stays disabled until you tick the box saying you have put them somewhere safe.

Each recovery code works once, in place of the app, and the card says how many are left. Sign in with one when your phone is gone, then regenerate the set.

To turn 2FA off, press Disable and enter a current code. The stored secret and any unused recovery codes are erased with it.

Every signed-in session is listed with its browser, its IP address, the day it started and the day it expires, seven days after it was opened unless the instance was configured otherwise. Your own is marked current session.

Revoke ends one of them. Sign out the others ends all but yours in one press. Neither asks for a password, because both are reachable only from inside your own session.

Privacy