What This Page Does
Security Settings lets you protect your account with modern authentication methods. Enable TOTP-based two-factor authentication, register WebAuthn/FIDO2 passkeys for passwordless login, manage active sessions, and review audit logs of security-relevant actions.
Getting Started
- Navigate to Settings → Security
- Enable 2FA — scan the QR code with your authenticator app
- Register a passkey — use your device's biometric or security key
- Review active sessions — see all logged-in devices
- Check audit logs — security events for the past 90 days
Key Features
- TOTP 2FA — time-based one-time passwords via any authenticator app
- WebAuthn passkeys — passwordless login using biometrics or security keys
- Session management — view and revoke active sessions on any device
- Audit logs — login attempts, role changes, API key generation, data exports
Tips & Best Practices
- Enable 2FA as your first action after account creation
- Register 2+ passkeys on different devices as backup
- Review active sessions monthly and terminate any you don't recognise
- Export audit logs for compliance documentation