Two-factor authentication and passkeys

Your account has no email address, and that cuts both ways.

Email address none on this account
For you
There is no password reset.
For an attacker
There is no recover-by-email path either.

The password is the only thing standing between someone and your account, so a second factor is worth the two minutes.

Authenticator app (TOTP)

Settings Sign-in Set up

  1. 01
    Scan the QR code with any authenticator app.
  2. 02
    Enter one code to confirm the clock agrees.
  3. 03
    Save the recovery codes. They are shown exactly once and are not recoverable afterwards, because they are stored hashed, so nobody here can read them back to you.
Single use
Spent
A recovery code
Each one works once. A code you have used is spent.
A login code
The same six digits cannot be replayed inside their thirty-second window, even by someone who watched you type it.

Passkeys

Settings Sign-in Add a passkey

Your device's own unlock (fingerprint, face, or PIN) becomes the login.

Nothing typeable is exchanged.

That is what makes a passkey resistant to phishing in a way a code is not.

Register more than one if you can: a laptop and a phone, say.

A passkey lives on the device that made it, and a single passkey plus a lost device is a bad afternoon.

No SMS, no email

SMS
Email

Neither is offered, and that is deliberate. Both are recoverable by someone who controls the phone number or the mailbox, which would quietly undo the reason this account has no email address in the first place.

Something missing or wrong here? Say so. The documentation is part of the product, not an afterthought. All topics · Legal & privacy · Home