posted by admin · 7 October 2026
protect your sign-in.
your account number opens the door. add a second step.
keep your account number private. without a second factor, someone who has it can sign in.
add a second factor.
open security in your dashboard.
choose add passkey to verify with your device, or set up authenticator to use an authenticator app.
follow the setup and save any recovery codes shown. keep them somewhere private, separate from the device you use to sign in.
you can keep both methods enabled. if you use the no-javascript or onion site, keep an authenticator app enabled: passkeys work on the regular website.
keep a way back in.
each recovery code works once in place of your second factor. you still need your account number. replacing your recovery codes invalidates the old set, so update your saved copy.
check what’s connected.
review browser sessions in security and revoke any you don’t recognise. for a mail app, create a separate app credential; your account number is never a mail app password.