Account security
Two-factor authentication, active sessions and API tokens.
Two-factor authentication
Section titled “Two-factor authentication”- Open Settings → Account.
- Start two-factor authentication setup.
- Scan the QR code with an authenticator app.
- Enter a current code to confirm that the app is configured correctly.
- Save the recovery codes before closing the dialog.
Store the recovery codes away from the device that runs your authenticator app. Regenerating them invalidates the old set.
Active sessions
Section titled “Active sessions”Account settings list active browser and API sessions with type, network address, and last activity.
You can revoke one session, or every session except the current one. Revoking sessions doesn’t revoke API tokens; revoke those separately.
API tokens
Section titled “API tokens”Create personal access tokens for the REST API and MCP server. A token can have an optional expiry and is shown once at creation. See API tokens and MCP server.