Password, two-factor authentication and sessions
What protects your account, the real durations, and the delays worth knowing in advance — including the one that reopens an account you have lost everything for.
The password
Twelve characters minimum. No composition rule — no mandatory capital, no imposed special character: those rules produce short, predictable passwords, which length avoids better.
It is changed from Settings › Profile.
Forgotten password
The form answers the same thing whether the address exists or not. That is deliberate: a form that says “unknown account” is a tool for finding out who your customers are.
The link you receive is single-use and lasts one hour. Opening it has an effect few tools apply:
Opening the link ends all your other sessions. Without that, changing your password evicted nobody — and it is precisely when you suspect an intrusion that you change your password.
Three sends per hour per recipient address, on top of a per-IP limit.
Two-factor authentication
TOTP, from Settings › Security: you scan a QR code with the authenticator app of
your choice. Once active, it is asked for at every sign-in.
Your organization may require it. In that case, until you turn it on, you stay signed in and can still read everything — but creating, changing or deleting anything is refused, with a message pointing you back here. Access returns the moment you enrol, with no need to sign in again.
The requirement belongs to the organization, not to your account: if you belong to several, it applies only in the one that set it. And a passkey does not stand in for it — it is worth two factors on its own, but the rule currently speaks of one-time codes.
You have lost your phone and your backup codes
There is a way out, and it takes 72 hours.
From the screen asking for your code, choose “levée après un délai de sécurité”. You enter your password as usual — that is what proves it is you — and the request is recorded. Three days later, when you sign in again, you will be able to lift two-factor authentication.
What happens in between:
- You receive a message containing a link that cancels the request in one click.
- The owners and administrators of your organizations are told, without that link: they are informed, they do not decide for you.
- A banner appears in every session you still have open, with the same cancel button. If you are still signed in somewhere, you do not even need the email.
At term, the lift destroys your authenticator app, your backup codes and your trusted devices, and closes every session. You sign in with your password alone, then enrol a new second factor.
This delay is the protection, not a slow process. Without it, somebody who stole your password would strip your two-factor authentication in a minute. With it, they would have to still hold that password three days later without you having read a single one of our messages.
We cannot shorten it, and nobody here will offer to. This is not an internal rule somebody could bend: there is no button, for anyone, that speeds a request up. That is what makes a convincing phone call insufficient to get into your account.
If you still have a passkey, this path is refused — and that is good news: a passkey signs you in on its own, with no code. Go back to the sign-in screen and choose the passkey option.
Three requests per day at most. Cancelling and asking again in a loop does not move the deadline; it only fills your mailbox.
Sessions
Settings › Security lists your active sessions and lets you revoke them. A session
lasts seven days.
The delay to know about: a revoked session may keep answering for up to five minutes. The session cookie carries a signed copy of its state, and deleting a row in the database does not reach a cookie already sitting in a browser. The screen says so before the click rather than implying an instant effect.
If five minutes is five minutes too many, change the password: opening the reset link cuts everything, immediately.
Address verification
A link valid for 24 hours is sent at sign-up. Until it is opened, the account can sign in but writes nothing — see premiers-pas.
The address stays editable in Settings › Profile for as long as it is unconfirmed,
which handles the most frequent case: a typo at sign-up.
Signing in with Google, signing in with SSO
The Google button only appears if the instance really has Google credentials. SSO sign-in works by address domain and assumes a configured, verified provider — see sso.
Deleting your account
Settings › Profile, danger zone. You have to type SUPPRIMER, then confirm through
a link sent to your address: two deliberate gestures for an irreversible action.
Your inboxes, your messages and your API keys are deleted, backups included.
Deleting your account is not deleting the organization: see organisation.