# Account security

> Protect your ZeroCaptcha sign-in with an authenticator app, recovery codes and passkeys, manage your sessions, and see what needs a recent sign-in.

Source: https://zerocaptcha.io/docs/account-security

Your dashboard sign-in controls your keys and your balance, so it is worth a second factor. Two-factor
is optional: nothing requires it, and the dashboard only suggests it. A confirmed email address is
needed before you create an API key or add funds.
Everything on this page is under **Settings** in the dashboard.

## Passwords

A password needs at least 8 characters, and may not be your email address or a common password. A
password manager's generated password passes. Forgot it? **Forgot password** on the sign-in page
emails a link that works once, for 30 minutes. A new password, by reset or from Settings, signs out
every other session, forgets the devices you signed in on, and is emailed to you. A reset does not
sign you in: sign in with the new password, and your second factor if you have one.

## Two-factor authentication

Once any second factor is on, signing in with your password asks for one more step.

### Authenticator app

Any app that supports time-based codes (TOTP) works: 6 digits, a new code every 30 seconds.

1. On **Settings**, turn on the authenticator app and confirm your password.
2. Scan the QR code, or type the key it shows, into your app.
3. Enter a code from the app within 15 minutes. Two-factor is on only once you confirm.

Each code works once. Turning the app off needs a second factor, never your password alone, and
turning it on or off is emailed to you.

### Recovery codes

When you turn on the authenticator app you get 10 recovery codes: each works once, in place of a
code from the app, if you lose your phone. Store them somewhere other than your phone, such as a
password manager. You can make a new set at any time, which replaces the old one. Dashes, spaces and
capitals do not matter when you type one.

### Passkeys

A passkey signs you in with your device's fingerprint, face or PIN, with no password and no second
step: it is two factors in one. Add one on **Settings** (up to 20), name it, and remove it there.
Adding or removing a passkey asks you to confirm it is you, and is emailed to you. An account always
keeps a way in: you cannot remove your last passkey while you have no password. You can also sign up
with a passkey instead of a password.

## Sessions

You stay signed in for up to 30 days, and are signed out after 24 hours without activity. **Settings**
lists every session: the browser it was opened in, its address, and when it was last active. End any
one of them, or every session but the one you are using, when a device is lost or shared.

## Changes that need a recent sign-in

Changing your email address or your password, and adding or removing a second factor, needs you to
have signed in, or confirmed your password, within the last 10 minutes. The dashboard asks when it
needs to. Managing API keys never needs it.

## Email verification

Confirm your email address by opening the link we send when you sign up. Until you do, creating an
API key and adding funds are refused with
[`email_unverified`](https://zerocaptcha.io/docs/reference/errors#email_unverified), so receipts and security emails
always reach you; everything else in the dashboard works. The link works for 24 hours; you can ask
for another after a minute. While you change your address, your confirmed one stays in use until
the new one is confirmed.

## Security emails

We email you when your password changes, when your email address moves (to the old address, if it was verified),
when two-factor is turned on or off, when recovery codes are made or one is used, when a passkey is
added or removed, and when a new device signs in. If you didn't make the change, reset your password
and write to support.

## If your account is suspended

A person suspends an account after a report or a check of our logs; nothing does it automatically.
Everyone on the account is emailed, with how to appeal. While it lasts, its API keys are refused and
it can't make tasks, keys or top-ups, but you can still sign in and read everything. To appeal, open
**Support** in the dashboard: the form becomes an appeal, which a person reads and answers by email.
If the suspension is lifted, everyone is emailed again and the keys work at once.

## Your data and deleting the account

**Settings › Your data** downloads a copy of your data as a JSON file. An owner's covers the account:
its people, keys (never the key itself), balance, credits, top-ups, receipts, usage, newest 1,000
tasks, messages to support and activity. A member's covers them.

**Settings › Delete account**, for owners, deletes the account at once and for good. It asks for your
password or a passkey, and says what is lost first:

- Every API key stops working, and tasks still queued are cancelled uncharged.
- Everyone on the account is signed out, and their sign-in and personal data are erased: addresses,
  passwords, sessions, two-factor and passkeys, billing details, messages to support and the
  activity log.
- **Any balance left is lost:** top-ups are final, so it is not refunded.
- What the law and our books need stays: charges, credits, top-ups and receipts, under the name
  "Deleted account", and task records until their retention ends, without their tokens. See the
  [Privacy Policy](https://zerocaptcha.io/legal/privacy).

## Sign-in protection

Sign-in attempts are rate-limited per address and per account, and a device that fails too often is
forgotten, so a password cannot be guessed quickly. A code from the authenticator app counts toward
the same limits. Your password is never stored, only a slow hash of it.
