Passkeys and 2FA
Secure your account with TOTP, recovery codes, and WebAuthn.
TOTP authenticator
Open /<orgSlug>/settings → Security → Authenticator app. Scan the QR code, save the recovery codes, and confirm with a live code.
Passkeys
Add a Passkey on the same page. Passkeys satisfy step-up for sensitive dashboard actions (API key minting, project sharing, skill edits).
Phone verification
Verify your phone to unlock the EARLY_BIRD 1,000-credit promotion — see Billing.
Step-up expiry
Step-up lasts about ten minutes. If a sensitive action fails with 403, re-authenticate with passkey or TOTP and retry.