Account security
More
Your dashboard sign-in controls your keys and your balance, so it is worth a second factor. Two-factor is optional: nothing requires it, and the dashboard only suggests it. A confirmed email address is needed before you create an API key or add funds. Everything on this page is under Settings in the dashboard.
Passwords
Section titled “Passwords”A password needs at least 8 characters, and may not be your email address or a common password. A password manager’s generated password passes. Forgot it? Forgot password on the sign-in page emails a link that works once, for 30 minutes. A new password, by reset or from Settings, signs out every other session, forgets the devices you signed in on, and is emailed to you. A reset does not sign you in: sign in with the new password, and your second factor if you have one.
Two-factor authentication
Section titled “Two-factor authentication”Once any second factor is on, signing in with your password asks for one more step.
Authenticator app
Section titled “Authenticator app”Any app that supports time-based codes (TOTP) works: 6 digits, a new code every 30 seconds.
- On Settings, turn on the authenticator app and confirm your password.
- Scan the QR code, or type the key it shows, into your app.
- Enter a code from the app within 15 minutes. Two-factor is on only once you confirm.
Each code works once. Turning the app off needs a second factor, never your password alone, and turning it on or off is emailed to you.
Recovery codes
Section titled “Recovery codes”When you turn on the authenticator app you get 10 recovery codes: each works once, in place of a code from the app, if you lose your phone. Store them somewhere other than your phone, such as a password manager. You can make a new set at any time, which replaces the old one. Dashes, spaces and capitals do not matter when you type one.
Passkeys
Section titled “Passkeys”A passkey signs you in with your device’s fingerprint, face or PIN, with no password and no second step: it is two factors in one. Add one on Settings (up to 20), name it, and remove it there. Adding or removing a passkey asks you to confirm it is you, and is emailed to you. An account always keeps a way in: you cannot remove your last passkey while you have no password. You can also sign up with a passkey instead of a password.
Sessions
Section titled “Sessions”You stay signed in for up to 30 days, and are signed out after 24 hours without activity. Settings lists every session: the browser it was opened in, its address, and when it was last active. End any one of them, or every session but the one you are using, when a device is lost or shared.
Changes that need a recent sign-in
Section titled “Changes that need a recent sign-in”Changing your email address or your password, and adding or removing a second factor, needs you to have signed in, or confirmed your password, within the last 10 minutes. The dashboard asks when it needs to. Managing API keys never needs it.
Email verification
Section titled “Email verification”Confirm your email address by opening the link we send when you sign up. Until you do, creating an
API key and adding funds are refused with
email_unverified, so receipts and security emails
always reach you; everything else in the dashboard works. The link works for 24 hours; you can ask
for another after a minute. While you change your address, your confirmed one stays in use until
the new one is confirmed.
Security emails
Section titled “Security emails”We email you when your password changes, when your email address moves (to the old address, if it was verified), when two-factor is turned on or off, when recovery codes are made or one is used, when a passkey is added or removed, and when a new device signs in. If you didn’t make the change, reset your password and write to support.
If your account is suspended
Section titled “If your account is suspended”A person suspends an account after a report or a check of our logs; nothing does it automatically. Everyone on the account is emailed, with how to appeal. While it lasts, its API keys are refused and it can’t make tasks, keys or top-ups, but you can still sign in and read everything. To appeal, open Support in the dashboard: the form becomes an appeal, which a person reads and answers by email. If the suspension is lifted, everyone is emailed again and the keys work at once.
Your data and deleting the account
Section titled “Your data and deleting the account”Settings › Your data downloads a copy of your data as a JSON file. An owner’s covers the account: its people, keys (never the key itself), balance, credits, top-ups, receipts, usage, newest 1,000 tasks, messages to support and activity. A member’s covers them.
Settings › Delete account, for owners, deletes the account at once and for good. It asks for your password or a passkey, and says what is lost first:
- Every API key stops working, and tasks still queued are cancelled uncharged.
- Everyone on the account is signed out, and their sign-in and personal data are erased: addresses, passwords, sessions, two-factor and passkeys, billing details, messages to support and the activity log.
- Any balance left is lost: top-ups are final, so it is not refunded.
- What the law and our books need stays: charges, credits, top-ups and receipts, under the name “Deleted account”, and task records until their retention ends, without their tokens. See the Privacy Policy.
Sign-in protection
Section titled “Sign-in protection”Sign-in attempts are rate-limited per address and per account, and a device that fails too often is forgotten, so a password cannot be guessed quickly. A code from the authenticator app counts toward the same limits. Your password is never stored, only a slow hash of it.