Security and sessions
Change your password, manage connected providers, and review the devices logged into your account.
Everything on this page lives under Account settings, then Security.
Change your password
Enter your current password. This proves the session belongs to you and not to someone who found an unlocked laptop.
Enter the new password twice. It needs at least eight characters, and the strength meter tells you when it is comfortably strong.
Confirm. Other sessions are signed out, the current one stays active, and we email you a notice.
Use a password manager and a unique password. Length beats complexity: a long passphrase is stronger and easier to type than a short string of symbols.
Set a password after a social sign up
If you created your account with Google or GitHub, the security page offers Set a password instead of Change password. We send a link to your verified address, and the link lets you choose a password without entering a previous one, since there is none.
Adding a password does not disconnect the provider. You end up with two ways to log in.
Connected providers
The Connected accounts section lists Google and GitHub with their status.
- Connect links a provider to your existing account, using the same email address. Afterwards either method logs you in.
- Disconnect removes the link. It is refused when it would leave you with no way to log in, so set a password first.
Reset a forgotten password
From the login screen, choose Forgot password. We send a link valid for one hour to your verified address. Opening it lets you set a new password and signs out every other session.
We always answer the reset form with the same confirmation message, whether or not an account exists for that address. This prevents using the form to discover who has an account.
Active sessions
The session list shows every browser and device currently logged in, with the approximate location, the browser name and the date of the last activity. Your current session is labelled.
Choose Revoke on a line to sign that device out immediately, or Sign out everywhere else to keep only the session you are using.
Review the list if something looks wrong
A session you do not recognize is a reason to revoke everything and change your password in the same visit. Sessions expire on their own after 30 days without activity.
Emails we send about security
We notify you when your password changes, when your email address changes, when a provider is connected or disconnected, and when a login comes from a device we have not seen before. These messages cannot be disabled in Notifications, because their whole purpose is to warn you about an account takeover.