Knowledge base
Account security
Two-factor from an authenticator app, ten recovery codes, and a password even if you signed up with Google.
Details
- You sign in with Google, GitHub, or an email and password. Signing up with a provider leaves the account without a password of its own, and Settings → Account offers to set one so that both routes work from then on: the provider button and the password form reach the same account. Changing a password that already exists asks for the current one first.
- Two-factor is an authenticator app — Google Authenticator, 1Password, Authy, anything that reads a QR code. Six digits, rotating every thirty seconds. Turning it on asks for your password, shows the code to scan, and does not switch it on until you type six digits the app produced, so a secret that was scanned wrong is caught while you can still sign in rather than the next time you try. Turning it off asks for the password too.
- Ten recovery codes are shown once, at the end of that setup, and each one signs you in exactly once if the phone is gone. They are not shown again and cannot be read back out of the account later, so the moment to save them is while they are on the screen.
- A workspace can require it, from Settings → Workspace. It takes effect immediately, including for people who are already signed in: a member without an authenticator app meets a lockout screen instead of that workspace’s mail until they enrol, and an invitation cannot be accepted without it either. Turning the requirement back off lets everyone it had locked out straight back in.
- Deleting the account is on that same Account screen. It removes the account, every domain on it and all the mail those domains have received; it is confirmed by a link mailed to you rather than by the click alone; and it cannot be undone.