Skip to main content

Docs · Account and security

Account security

Strong passwords, two-factor codes with backup codes, passkeys, institution single sign-on, sessions you can see and revoke.

Updated 2026-09-12Open security settings

Passwords

At least ten characters; common passwords, your name and your e-mail are rejected both in the browser and on the server. Changing your password signs out every other device. Reset links are valid for one hour; reset also signs everything else out.

Two-factor authentication

  1. Settings → Security → Turn on two-factor; confirm your password.
  2. Scan the QR code with any authenticator app (or type the key) and enter the six-digit code.
  3. Save the backup codes; each works once if you lose the app.
  4. From then on, password sign-ins ask for a code. Tick “Trust this device” to skip it for 30 days on that device.

Two-factor protects password sign-ins. Passkeys are already phishing-resistant and do not ask for a code.

Passkeys

Face ID, Touch ID, Windows Hello or a hardware key. Add one per device (or a synced passkey from your password manager), then use “Continue with a passkey” on the sign-in page. Remove lost devices from the list.

Institution sign-in and linked accounts

If your administrator registered your institution's identity provider, “Continue with your institution” signs you in with your work address. Google and ORCID can be linked under Security for sign-in; ORCID does not share e-mail addresses, so create the account first, then link.

Devices and sessions

Every signed-in device is listed with browser, system, IP address and last activity. Sign out one, or all others. Sessions expire after 30 days of inactivity.

Protection against guessing

Sign-in, sign-up, reset and code endpoints are rate-limited per network address, and too many wrong codes lock two-factor for a while. Suspicious activity is visible in your sessions list.

Related

Something missing or wrong? Tell us.