Free trial · 14 days · Cancel anytimeGet started
Feature
v0.0.8-beta·

Two-factor authentication and passkeys

What's new

  • Settings > Security now lets you turn on two-factor authentication (TOTP). Enabling it walks you through three steps: confirm your password, scan the QR code with your authenticator app and enter the 6-digit code it generates, then save your one-time backup codes (shown only once). Turning it off asks for your password again.
  • Platform admin accounts must have two-factor authentication enabled. An admin without it is redirected to Settings > Security with a banner prompting them to set it up.
  • Once two-factor authentication is on, signing in with email and password is followed by a challenge screen asking for your 6-digit code, or one of your backup codes as an alternative.
  • You can also add a passkey from Settings > Security: a device biometric or a security key, for password-free sign-in. Registered passkeys are listed with the date they were added and a button to remove them.
  • The sign-in page now has a "Continue with a passkey" button next to Google and GitHub, so you can sign in without typing a password at all.