Account security
Manage email verification, GitHub login, authenticator 2FA and CLI access.
Email verification and GitHub
Email signup requires verification before project access. Request another verification email from the portal if needed. GitHub signup requires a verified primary GitHub email. Repository permissions are a separate connection.
To link GitHub to an existing email account, sign in normally and open Profile & settings → GitHub sign-in. Accounts are not automatically merged, even if email addresses match.
Passwords and authenticators
Set up authenticator 2FA in Profile & settings and save your recovery codes somewhere private. Each recovery code works only once. GitHub sign-in also prompts for your StaticWeb authenticator when it is enabled.
A GitHub-only account can add its first password within five minutes after signing in through GitHub. Leave Current password empty, choose a password of at least 12 characters, and save. Password changes sign out existing browser sessions. Revoke CLI tokens separately from CLI access.
Lost access
If you cannot access your email, GitHub account, or recovery codes, contact support. There is no automated password-reset flow in this release. Never send support your password, authenticator secret, or API keys.