Account security
- Written for
- + Written for
- Deprecated
- + Deprecated
- Applies to
- + Applies to
Account security
Dashboard → Settings → Security covers everything about how you (and your teammates) authenticate — password management, active sessions, and connected sign-in methods.
Password
If your account has a password set, a Change password card lets you update it — current password, new password (minimum 8 characters). Changing your password signs out your other active sessions as a safety measure.
Note: SSO-only accounts (created via Google, GitHub, or Discord with no password ever set) see a note explaining there's no password to manage instead of the change form — set one first if you want a password-based fallback login.
Sessions
Every device currently signed into your account is listed with:
A best-effort browser + OS label (parsed from the device's user agent).
The device's IP and how long ago it was last active.
A This device badge on the session you're currently using.
Click Revoke on any other session to sign it out immediately — useful after losing a device or noticing unfamiliar activity. Two broader actions sit below the list:
Action | Effect |
|---|---|
Sign out | Ends your current session only |
Sign out everywhere | Revokes every active session across all your devices |
Connected sign-in methods
Link or unlink OAuth providers — Google, GitHub, and Discord — from the same account. Each shows whether it's connected (and the linked email, when available) or offers a connect button.
Note: You can't disconnect your last remaining sign-in method — if you have no password and only one OAuth connection, unlinking it is blocked so you're never locked out of your own account.
Related: organization danger zone
Settings → Danger zone (separate from Security) holds the destructive, confirmation-gated actions: deleting the current organization, or deleting your entire account. Both require typing DELETE to confirm and are irreversible.
See also: Banner settings