Account Security & Two-Factor Authentication
Help articles may not be fully accurate — they can lag behind the app due to frequent updates and automated translation. If in doubt, please contact support.
On this page
- 1. Password
- 2. Email verification
- 3. Two-factor authentication (2FA)
- 4. Active sessions
- 5. IP allow-listing
- 6. Suspended accounts
- 7. Good to know
- 8. Troubleshooting
- 9. Related
Your password protects your account; the settings on this page add layers on top of it. This article walks through each one — what it does, how to turn it on, and what happens if you lose access to it.
Password
Changing your password (Profile → Change Password) requires your current password first, unless you signed up through a social login (Google, Facebook, or similar) — those accounts have no password you ever knew, so you set one directly. A new password must be at least 8 characters and include an uppercase letter, a lowercase letter, a number, and a special character.
If you are locked out entirely, use Forgot your password? on the sign-in page. The reset link emailed to you expires after 60 minutes; after that, request a new one.
Email verification
New accounts start unverified. Until you click the link in the verification email, some mail (and features that depend on a confirmed address) will not reach you. The link works even if you open it on a different device than the one you registered on — it does not require you to be logged in there, only that the link itself is valid and matches your current email. If it expired or never arrived, resend it from the notice banner or from Profile.
Two-factor authentication (2FA)
2FA adds a second step at sign-in: after your password, you enter a 6-digit code from an authenticator app (Google Authenticator, Authy, or similar).
Turning it on
- Go to Profile and click Enable Two-Factor.
- Scan the QR code with your authenticator app, or enter the secret shown underneath by hand if you cannot scan it.
- Type the 6-digit code your app now shows into the Verification Code field and confirm.
- You are immediately given 8 recovery codes. Save them somewhere other than the same phone your authenticator app lives on — a password manager or a printed copy.
From that point on, every sign-in asks for a code. If you have a code, use it; if you cannot generate one, enter a recovery code instead — each one works exactly once and is removed from your account the moment you use it, so they are for emergencies, not routine use.
Losing both your authenticator app and your recovery codes leaves no self-service way back in — that is the deliberate trade-off of adding a second factor. Contact support and be ready to prove your identity another way.
To turn 2FA off, open the same section and confirm with your current password. This removes the code requirement at sign-in immediately and invalidates any recovery codes you had left.
Your two-factor secret and recovery codes are never exposed through an ordinary profile edit — the platform deliberately keeps those two fields out of what a routine account update can touch, so enabling, confirming, or disabling 2FA are the only paths that ever change them.
Active sessions
Profile → Active Sessions lists every browser currently signed in, with its IP address, browser, and how long ago it was last active. If you do not recognize one, sign it out individually, or use Sign out all other sessions to end every session except the one you are using right now.
IP allow-listing
An administrator can restrict certain accounts to sign in only from a specific IP address or range. This is set up on the admin side, not from your own Profile page — if it applies to your account and you try to reach the platform from an IP outside the allowed list, you get an access-denied error rather than the normal sign-in screen. If that happens unexpectedly, contact whoever manages your organization's account.
Suspended accounts
If your account is suspended, you are signed out automatically the next time you interact with the platform, even mid-session — there is no warning first. Signing back in is blocked until the suspension is lifted; contact support if you believe this happened in error.
Good to know
- Two-factor authentication and your password are independent — enabling 2FA does not change your password requirements, and resetting your password does not disable 2FA.
- Deleting your account (Profile → Danger Zone) requires your current password and anonymizes your account and bookings immediately. This cannot be undone.
- Some sensitive actions may ask you to re-confirm your identity mid-session even while you are already signed in, as an extra check on top of everything above.
Troubleshooting
- My authenticator app shows a code but sign-in still rejects it — the code is time-based and only valid for a short window; make sure your phone's clock is correct and try the next code that appears.
- I lost my phone and cannot get a 2FA code — use one of your saved recovery codes at the sign-in screen instead of a 6-digit code.
- I used up all my recovery codes and lost my authenticator app — there is no self-service recovery at that point; contact support to verify your identity another way.
- I am not receiving the verification or password-reset email — check spam, confirm the address on your account is correct, and request a new link since old ones expire.
- I got signed out with a suspension message — your account has been suspended; this is not a bug, and you will need to contact support to resolve it.
- I get an access-denied error even though my password and 2FA code are correct — your account may be IP-restricted and you are connecting from an address that is not on the allowed list; contact your organization's administrator.