# Secure your account

> Source: https://elaichi.ai/docs/guides/settings/security/

Protect **your user account** (across every organization you belong to) with an authenticator app and optional passkeys. This tab is personal. An organization can also require every member to use a second factor — see [When your organization requires two-factor authentication](#when-your-organization-requires-two-factor-authentication) below, and [Require two-factor authentication](#require-two-factor-authentication-for-your-organization) if you administer one.

**Where to find it:** **Settings → Security**

No special org permission is required. Every signed-in member can manage their own factors here.

## Two-factor authentication (TOTP)

After social, magic-link, or SSO sign-in, Elaichi asks for a **6-digit code** from an authenticator app (1Password, Google Authenticator, Authy, and similar).

### Enroll

1. Open **Settings → Security**.
2. Under **Two-factor authentication**, choose **Set up two-factor authentication**.
3. Scan the QR code, or copy the secret into your app manually.
4. Enter the current 6-digit code and choose **Verify & enable**.
5. Elaichi shows **8 one-time recovery codes**. Copy or download them somewhere safe — **they are shown only this once**.
6. Choose **I saved my recovery codes**.

**You'll know it worked when:** The status shows active, and the next sign-in prompts for a code — see [Two-factor sign-in](/guides/basics/two-factor-sign-in).

### Recovery codes

- You receive **8** codes at enrollment (format like `xxxx-xxxx`).
- Each code works **once** if you lose the authenticator.
- **Regenerate recovery codes** issues a new set of 8 and invalidates the old ones. Save the replacements immediately. This requires [confirming it’s you](/guides/basics/confirming-sensitive-actions).

### Disable

**Disable two-factor authentication** turns TOTP off after step-up confirmation. Prefer regenerating recovery codes or fixing the authenticator before disabling in production accounts.

If an organization you belong to [requires two-factor authentication](#when-your-organization-requires-two-factor-authentication) and you have **no passkey**, the option is unavailable and says why. Add a passkey first.

## Passkeys

Sign in with Face ID, Touch ID, Windows Hello, or a security key.

| Action | Details |
| --- | --- |
| **Add passkey** | Optional label, then complete the browser/device ceremony |
| **Rename** | Edit the display name later |
| **Delete** | Removes that passkey after step-up confirmation |

Passkeys show as **Synced** or **Device-bound** depending on the credential.

:::callout{type="warning"}
If you have only one passkey and TOTP is not enabled, enable two-factor authentication before deleting that final passkey. Removing the last passkey requires TOTP confirmation.
:::

Adding or removing passkeys uses the same [Confirm it’s you](/guides/basics/confirming-sensitive-actions) flow as other sensitive account changes.

## How long you stay signed in

Every Elaichi session has two limits, the same for everyone and not configurable per organization:

| Limit | What happens |
| --- | --- |
| **8 hours without activity** | You are signed out automatically. Using Elaichi in any tab keeps you signed in. |
| **7 days in total** | You are signed out at the 7-day mark even if you have been active the whole time. Signing in again starts a new 7 days. |

When a session ends this way, Elaichi takes you to the sign-in screen with a short note saying why, and brings you back to the page you were on after you sign in. (If you stay away for more than about a week and a day, the note is not shown: the session has been cleaned up by then and you simply see the sign-in screen.) These limits are an automatic-logoff safeguard (for example for HIPAA).

They apply to signed-in browser sessions. [API tokens](/guides/settings/api-tokens) and connected apps have their own lifecycles and are not signed out by them.

## When your organization requires two-factor authentication

An organization owner or admin can require every member to use a second factor. If yours does and you have not shown one in your current session, Elaichi stops you before you reach that organization and opens **Set up two-factor authentication**. Choose an authenticator app or a passkey; with an authenticator app you also save your recovery codes. When you finish, you go straight back to the page you were opening. You do not need to sign in again.

- **You already have a second factor, but this session never used it.** For example, you signed in with Google before you enrolled. Elaichi asks you to sign in again, and your next sign-in asks for the code or passkey.
- **What counts.** A sign-in with a passkey. A sign-in where you entered your authenticator code. A factor you set up during the current session. A sign-in through **that organization's own SSO connection**, because the organization's identity provider has already applied its own policy.
- **What SSO does not cover.** An SSO sign-in counts only for the organization that owns the SSO connection. It does not satisfy a different organization's requirement.
- **Not affected.** API tokens, and Elaichi support sessions (which are time-limited and opt-in).
- **AI clients.** Connecting an app such as Claude is checked at consent, and an existing connection made without a second factor stops working until you set one up and connect again. The message names Elaichi as the place to do it.
- **You cannot remove your last second factor** while an organization you belong to requires one. Turning off the authenticator app needs a passkey; deleting your last passkey needs the authenticator app.

Enrolling an authenticator app when you have no other factor needs a recent sign-in. If it asks you to sign in again, do that and you come back to the setup page.

## Require two-factor authentication for your organization

**Where to find it:** **Settings → Organization → Security → Require two-factor authentication** (needs the **Manage organization** permission).

1. Turn on **Require two-factor authentication**.
2. The setting shows how many members have no second factor yet. Those members are asked to set one up the next time they open the organization. It is a count only; nobody is signed out the moment you switch it on.

The setting is **off by default**, for new organizations too.

- **You cannot lock yourself out.** If your own session has not shown a second factor, the switch is disabled and says so. Set up two-factor on your account (or sign in again with it) and the switch becomes available. The API answers `409 mfa_setup_required` if you try anyway.
- **Turning it off** needs [confirming it’s you](/guides/basics/confirming-sensitive-actions).
- **It is a signed-in-person setting.** It cannot be changed with an API token, from the AI assistant, or from a staff support session.
- **It is recorded.** The audit log's **Organization updated** entry shows the old and the new value.
- **Scope.** The requirement applies to this organization only. A member of several organizations is asked only when they open one that requires it.

## Sensitive actions

Disabling MFA, regenerating recovery codes, managing passkeys, and revoking API tokens all require a fresh proof of identity. Details: [Confirming sensitive actions](/guides/basics/confirming-sensitive-actions).

## Good to know

- A second factor belongs to your account globally. Whether it is *required* is a per-organization setting.
- Five failed MFA attempts during sign-in end the pending session — start sign-in again.
- Store recovery codes offline; they are as powerful as the authenticator for account unlock.

## Related

- [Confirming sensitive actions](/guides/basics/confirming-sensitive-actions)
- [Two-factor sign-in](/guides/basics/two-factor-sign-in)
- [Sign in](/guides/basics/sign-in)
- [Create API tokens](/guides/settings/api-tokens)
