Skip to main content
Ssnap Docs
Account

Account security

Sign-in options, two-factor authentication and profile controls.

Sign-in options

  • Email and password, with email verification on registration.
  • Google OAuth: sign in without a password. An OAuth account is linked to the email address it carries.
  • Password reset by email from the sign-in page.

Two-factor authentication

Enable 2FA under Settings → Security. Setup gives you a QR code for any TOTP app (1Password, Authy, Google Authenticator) plus recovery codes.

Store the recovery codes somewhere other than the device holding your authenticator. They are the only way back into an account whose second factor is lost.

Confirming or disabling 2FA requires your password.

Password changes

Change your password under Settings → Security. The page itself is password-confirmed, and password updates are throttled to 6 attempts per minute.

Profile

Settings → Profile holds your name, email address and avatar. Changing an email address triggers re-verification.

Deleting your account

Account deletion is available from the profile settings page and requires a verified email. It is permanent.

Deleting your user account is not the same as deleting a team. Review team ownership first, using Teams, so a team you own is not left without an owner.

API key hygiene

Account security ends where key handling begins: a key is a bearer credential with no second factor. Keep keys server-side, give them expiry dates, rotate them, and delete any key you cannot account for. See API keys.

Next