Documentation · Administration
Sign-in and security
Email and password or GitHub sign-in, the password rules, two-factor authentication with recovery codes, and requiring it for everybody.
Sign in with an email address and a password, or with GitHub. Add an authenticator app for a second factor, and require one for everybody in your organisation.
The sign-in page offers a work email and a password, or Continue with GitHub.
A password must be at least 12 characters, and must not be one that has turned up in a known data breach. To check that, we send the first five characters of a hash of the password to the Have I Been Pwned service, never the password or its whole hash. If that service cannot be reached, the check is skipped rather than leaving you unable to sign up.
Forgot your password? on the sign-in page sends a link to reset it.
There is no single sign-on: no SAML, no OpenID Connect provider of your own, and no SCIM. GitHub is the only other way in.
On Settings, the link beside Two-factor authentication opens the security page, where you add an authenticator app: scan the code it shows, or type the key, then enter a code from the app and press Verify and turn on. Authenticator apps are the only second factor; there are no passkeys or security keys.
Once it is on, we ask for a code after your password. We ask again before a sensitive action, such as a change to billing, a new API token or a change to who is in your organisation, when you last gave a code more than fifteen minutes before.
Under Recovery codes, Issue recovery codes gives you ten codes. Save them then: it is the only time they are shown, and we keep only a hash of each. A code is for when the authenticator is gone. Using one removes the authenticator, cancels the other codes, and signs you out everywhere; you then sign in with your password, set up a new authenticator, and issue new codes. Issuing new codes also stops every earlier code working.
An owner or an admin can turn on Require it for everyone, once they have an authenticator on their own account and have signed in with it. Somebody without a second factor is then sent to set one up before they can use the organisation.