The console uses a dedicated authentication service hosted on a separate `auth.` subdomain. You can sign in with email and password, a passkey, or a TOTP code once two-factor authentication is enabled.

## Sign in

Open the console sign-in page. Enter your email and password, then submit. If your browser has a registered passkey, the email field offers it as an autofill suggestion; you can also use the **Sign in with a passkey** button to start the WebAuthn ceremony directly.

If your account requires a second factor, you are redirected to the verify-TOTP page after the password check passes. Enter the six-digit code from your authenticator app.

If your email address is not yet verified, sign-in is blocked and the page offers a **Resend verification email** action.

## Enable two-factor authentication

Open **Settings → Security** and find the **Two-Factor Authentication** section. Click **Enable two-factor authentication**, confirm your current password, then scan the QR code with an authenticator app such as 1Password, Authy, or Google Authenticator. Enter the six-digit code the app generates to verify the setup.

After verification the console displays a one-time list of backup codes. Save them in your password manager — they are shown only once and are cleared from the screen automatically after five minutes.

## Use a backup code

If you lose access to your authenticator app, use a backup code on the verify-TOTP screen instead of a TOTP code. Each backup code can be used only once. After signing in, regenerate the list under **Settings → Security**, in the **Two-Factor Authentication** section, **Regenerate backup codes**.

## Lose your authenticator

If you also lose your backup codes, contact platform support. There is no self-service way to disable 2FA without either an authenticator code or a backup code, and organization administrators cannot disable 2FA on a member's behalf.

## Passkeys

You can register passkeys under **Settings → Security → Passkeys**. Passkey registration requires a session created in the last five minutes; if your session is older, the console prompts you to sign in again first.