Appearance
Account security
Your password, two-factor authentication and passkeys are managed on one page. Open the user menu at the bottom of the sidebar (your name) and choose Account security.
These settings belong to your account, not to a project: they apply to every project you are a member of.
Password
Under Password, enter your Current password, then the New password twice, and click Update password.
Two-factor authentication
Two-factor authentication (2FA) asks for a 6-digit code from an authenticator app (1Password, Google Authenticator, Authy…) every time you log in, on top of your password.
Turning it on
- Click Enable two-factor authentication. You may be asked to confirm your password first.
- Scan the QR code with your authenticator app, or type the key shown under Or enter this code manually.
- Enter the code the app generates in Authentication code and click Confirm.
2FA is only active once the code is confirmed. The card then shows Enabled.
Recovery codes
Recovery codes let you log in if you lose access to your authenticator app.
- Show recovery codes displays them. Store them somewhere safe, such as a password manager.
- Each code works once.
- Regenerate recovery codes replaces the whole set; the old codes stop working.
To use one, click Use a recovery code on the login code screen and enter it under Recovery code.
TIP
Viewing or regenerating recovery codes, and enabling or disabling 2FA, require a recent password confirmation. Diggama asks for your password again if you last confirmed it more than three hours ago.
Turning it off
Click Disable two-factor authentication and confirm. You will no longer be asked for a code when logging in.
Passkeys
A passkey is a credential stored on your device (Touch ID, Windows Hello, a phone) or on a hardware security key, which lets you sign in without typing a password.
Adding a passkey
- Click Add a passkey.
- Give it a Name you will recognise later, such as MacBook Touch ID.
- Click Continue and follow your browser's prompt.
Each passkey is listed with the date it was added and when it was last used. You can register several: one per device, for example.
Removing a passkey
Click the trash icon next to it and confirm with Remove. That passkey can no longer be used to sign in.