QS
Dashboard Data Models Projects People Activity Your account

Your account

Your password, and the second step that goes with it. Nothing here affects anyone else's account.

Password

Changing it signs out every other browser you are signed in on. If the reason for changing it is that somebody else knows the old one, that is the point.

Two-step sign-in

  1. Open your authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Authy — any of them) and add an account by entering a key manually.
  2. Give it this key:
    Account name: · type: time-based · 6 digits · 30 seconds. If your app takes a link instead, this is it:
  3. Type the six digits it is showing you now:

Nothing changes until that code is accepted. If you close this page now, your sign-in stays exactly as it is.

Write these down now. They are the only way back into your account if you lose your phone, each one works once, and this is the only time they are shown. They are stored hashed — nothing here can give them back to you.

If you lose your phone and your recovery codes

Somebody with server access runs this and your account goes back to password-only sign-in:

python -m app.cli disable-2fa --username your-username

It is written in the activity log like every other change. There is no way to do it from this page, and that is deliberate — otherwise it would not be a second factor.