Skip to content

Account & Security

A guide to protecting and managing your account. For two-factor authentication, see the MFA guide.

Manage passwords in Settings → Security. Passwords must be at least 8 characters (up to 128) and include letters and digits.

Accounts created with Google / GitHub have no password. Use “Set password” to add one so you can also log in with email + password.

Social Login Connections (Google / GitHub)

Section titled “Social Login Connections (Google / GitHub)”

Link and unlink under “Connected accounts” in Settings → Security.

  • If an existing account uses the same email address, the OAuth account is linked automatically on first login
  • When unlinking is unavailable: with no password and only one linked account, unlinking is blocked so you don’t lose your only sign-in method. Set a password first

Change it in Settings → Account. Confirm your identity with your password, or — if you have none — a 6-digit code sent by email. The change is finalized by opening the confirmation link sent to the new address.

High-impact operations — creating or deleting API keys, deleting your account, disabling MFA, changing IP restrictions — prompt for re-authentication (e.g. your password). The confirmation stays valid for 15 minutes.

Logging in from the CLI or MCP Server asks you to approve an authorization code in the browser. Approval issues an API key for the external tool automatically.

Download your account data as JSON from Settings → Account (paid plans, team owners only).

Delete from the danger zone in Settings → Account.

  • Confirming schedules the deletion; all data is permanently deleted after 30 days
  • To cancel during the grace period, contact support via the contact form