Secure your account
Protect your user account (across every organization you belong to) with an authenticator app and optional passkeys. This tab is personal. An organization can also require every member to use a second factor — see When your organization requires two-factor authentication below, and Require two-factor authentication if you administer one.
Where to find it: Settings → Security
No special org permission is required. Every signed-in member can manage their own factors here.
Two-factor authentication (TOTP)
After social, magic-link, or SSO sign-in, Elaichi asks for a 6-digit code from an authenticator app (1Password, Google Authenticator, Authy, and similar).
Enroll
- Open Settings → Security.
- Under Two-factor authentication, choose Set up two-factor authentication.
- Scan the QR code, or copy the secret into your app manually.
- Enter the current 6-digit code and choose Verify & enable.
- Elaichi shows 8 one-time recovery codes. Copy or download them somewhere safe — they are shown only this once.
- Choose I saved my recovery codes.
You'll know it worked when: The status shows active, and the next sign-in prompts for a code — see Two-factor sign-in.
Recovery codes
- You receive 8 codes at enrollment (format like
xxxx-xxxx). - Each code works once if you lose the authenticator.
- Regenerate recovery codes issues a new set of 8 and invalidates the old ones. Save the replacements immediately. This requires confirming it’s you.
Disable
Disable two-factor authentication turns TOTP off after step-up confirmation. Prefer regenerating recovery codes or fixing the authenticator before disabling in production accounts.
If an organization you belong to requires two-factor authentication and you have no passkey, the option is unavailable and says why. Add a passkey first.
Passkeys
Sign in with Face ID, Touch ID, Windows Hello, or a security key.
| Action | Details |
|---|---|
| Add passkey | Optional label, then complete the browser/device ceremony |
| Rename | Edit the display name later |
| Delete | Removes that passkey after step-up confirmation |
Passkeys show as Synced or Device-bound depending on the credential.
If you have only one passkey and TOTP is not enabled, enable two-factor authentication before deleting that final passkey. Removing the last passkey requires TOTP confirmation.
Adding or removing passkeys uses the same Confirm it’s you flow as other sensitive account changes.
How long you stay signed in
Every Elaichi session has two limits, the same for everyone and not configurable per organization:
| Limit | What happens |
|---|---|
| 8 hours without activity | You are signed out automatically. Using Elaichi in any tab keeps you signed in. |
| 7 days in total | You are signed out at the 7-day mark even if you have been active the whole time. Signing in again starts a new 7 days. |
When a session ends this way, Elaichi takes you to the sign-in screen with a short note saying why, and brings you back to the page you were on after you sign in. (If you stay away for more than about a week and a day, the note is not shown: the session has been cleaned up by then and you simply see the sign-in screen.) These limits are an automatic-logoff safeguard (for example for HIPAA).
They apply to signed-in browser sessions. API tokens and connected apps have their own lifecycles and are not signed out by them.
When your organization requires two-factor authentication
An organization owner or admin can require every member to use a second factor. If yours does and you have not shown one in your current session, Elaichi stops you before you reach that organization and opens Set up two-factor authentication. Choose an authenticator app or a passkey; with an authenticator app you also save your recovery codes. When you finish, you go straight back to the page you were opening. You do not need to sign in again.
- You already have a second factor, but this session never used it. For example, you signed in with Google before you enrolled. Elaichi asks you to sign in again, and your next sign-in asks for the code or passkey.
- What counts. A sign-in with a passkey. A sign-in where you entered your authenticator code. A factor you set up during the current session. A sign-in through that organization's own SSO connection, because the organization's identity provider has already applied its own policy.
- What SSO does not cover. An SSO sign-in counts only for the organization that owns the SSO connection. It does not satisfy a different organization's requirement.
- Not affected. API tokens, and Elaichi support sessions (which are time-limited and opt-in).
- AI clients. Connecting an app such as Claude is checked at consent, and an existing connection made without a second factor stops working until you set one up and connect again. The message names Elaichi as the place to do it.
- You cannot remove your last second factor while an organization you belong to requires one. Turning off the authenticator app needs a passkey; deleting your last passkey needs the authenticator app.
Enrolling an authenticator app when you have no other factor needs a recent sign-in. If it asks you to sign in again, do that and you come back to the setup page.
Require two-factor authentication for your organization
Where to find it: Settings → Organization → Security → Require two-factor authentication (needs the Manage organization permission).
- Turn on Require two-factor authentication.
- The setting shows how many members have no second factor yet. Those members are asked to set one up the next time they open the organization. It is a count only; nobody is signed out the moment you switch it on.
The setting is off by default, for new organizations too.
- You cannot lock yourself out. If your own session has not shown a second factor, the switch is disabled and says so. Set up two-factor on your account (or sign in again with it) and the switch becomes available. The API answers
409 mfa_setup_requiredif you try anyway. - Turning it off needs confirming it’s you.
- It is a signed-in-person setting. It cannot be changed with an API token, from the AI assistant, or from a staff support session.
- It is recorded. The audit log's Organization updated entry shows the old and the new value.
- Scope. The requirement applies to this organization only. A member of several organizations is asked only when they open one that requires it.
Sensitive actions
Disabling MFA, regenerating recovery codes, managing passkeys, and revoking API tokens all require a fresh proof of identity. Details: Confirming sensitive actions.
Good to know
- A second factor belongs to your account globally. Whether it is required is a per-organization setting.
- Five failed MFA attempts during sign-in end the pending session — start sign-in again.
- Store recovery codes offline; they are as powerful as the authenticator for account unlock.