Trusted devices & 2FA
What a trusted device is, how long it lasts, how to see and revoke every one of them, and which sessions still need a fresh code.
Two-factor authentication (2FA)
Add a second factor to your account from Profile → Security. Set up 2FA by scanning the QR code into an authenticator app (Google Authenticator, 1Password, Authy…) and confirming the 6-digit code it shows — the secret is only activated once you confirm a code, so an abandoned setup never locks you out. From then on, each sign-in asks for the current 6-digit code.
You can tick “don't ask for a code on this device for 30 days” at login to trust that device (the password is still required every time); Profile → Security lists every trusted device with a Revoke button per device and “revoke all / log out everywhere”.
To turn 2FA off, open Profile → Security and click Disable 2FA: you are asked for the current 6-digit code from your authenticator app, and that is the only thing you need to type — there is no separate password prompt, so it also works on a session you started from an emailed sign-in link. Disabling 2FA also clears every trusted device, because a device that skipped the removed factor must not keep that exemption.
A session started from an emailed sign-in link (a magic link) is treated as unproven: when 2FA is on, changing your password, disabling 2FA or adding a passkey asks for a fresh code, so a stolen inbox cannot strip the second factor. Each code is single-use — if a prompt is submitted twice, use the fresh code your app shows next, not the previous one.
Trusted devices
When 2FA is enabled you can tick “don't ask for a code on this device for 30 days” at login — that device is then trusted and skips the 2FA code (the password is still required).
Profile → Security lists every trusted device (label, IP, first trusted, expiry) with a Revoke button per device, plus “revoke all / log out everywhere”.
Revocation is immediate: the next login on a revoked device asks for a 2FA code again. Changing your password or disabling 2FA also clears all trusted devices.
AI agents see and revoke the same list over MCP with list_trusted_devices, revoke_trusted_device and revoke_all_trusted_devices.
Sessions that need a fresh code
A session created through a magic link is marked as a magic session. With 2FA enabled, a sensitive action in such a session — changing the password, disabling 2FA, adding a passkey — asks for a fresh 2FA code.
A normal password login and an account without 2FA are unaffected.
Passkeys (sign in without a password)
A passkey lets you sign in with your face, fingerprint or device PIN instead of typing a password. Register one from Profile → Security → Register passkey: your browser asks your device to create it, and the passkey appears in the list with the date it was added.
Once you have one, the login page offers a passkey button before you type anything, because signing in with a passkey starts from a list of your credentials rather than an email address. Press the button, approve the prompt, and you are in — nothing is typed.
Each passkey is bound to one device or password manager (iCloud Keychain, Google Password Manager, 1Password, a security key), so add one per device you sign in from, and remove any you no longer use with the delete button on its row. Deleting a passkey stops it working immediately, and you can always sign in the ordinary way instead.
If a passkey was added before this flow was fixed it may have been stored as a non-discoverable credential, which the login button cannot use. Delete that row and register a new passkey, which is made discoverable so the button finds it — the login page's button is the one that is refused, and re-registering is the only recovery.
Adding a passkey from a magic-link session asks for a fresh 2FA code, the same as changing your password or disabling 2FA.
See the MCP tool reference for the exact tool signatures, and Profile → Security in the dashboard for the list itself.