# Security

> Two-factor authentication, passkeys, and seeing where you are signed in.

![blueprint:josh/securing-your-account](https://blueprintr.io/embed/josh/securing-your-account?exclude=cmtpwdx7j000jybbheum4kptm&hideTabBar=1#h=620)

## Passkeys

A passkey is held by your device or password manager, cannot be phished, and
signs you in with the same gesture you unlock your device with.

Register more than one, such as a phone and a laptop, or a passkey and a
hardware key, so losing a device does not lock you out.

## Two-factor authentication

An authenticator app generating a time-based code, as a second step after your
password.

> [!IMPORTANT]
> Save your recovery codes somewhere that is not the device running the
> authenticator.

## Sessions

**Settings → Sessions & devices** lists everywhere you are currently signed in,
with device and approximate location. Revoke any you do not recognise.

Signing out revokes the session everywhere it is held, including the desktop
app.

## Organisation requirements

An organisation can require two-factor authentication for its members. Where it
does, you will be asked to set it up before you can reach the organisation's
content.
