account

account security

two-factor, passkeys, active sessions and login history.

all in settings, under security.

two-factor authentication

turn it on and logging in with your password also asks for a code from an authenticator app. you scan a qr code to set it up, and you get a set of recovery codes.

save the recovery codes somewhere that is not your phone. each one works once, and they are what gets you back in if you lose the authenticator.

signing in with discord or google does not ask for a code, because that login is protected by the other account's own security. if you sign in that way, put two-factor on that account too.

passkeys

a passkey signs you in with your device: a fingerprint, your face, or your screen lock. there is nothing to type and nothing to phish, since a passkey only works on the site it was made for. you can register more than one, so a lost phone is not a lockout.

sessions and history

  • active sessions lists everywhere you are signed in, with the device and when it was last used. you can sign any of them out, which is what to do if you used a shared computer.
  • login history shows recent attempts, including failed ones and ones that failed at the two-factor step. an attempt you do not recognise means change your password.

still stuck? ask in the discord, someone will know.