How You Sign In
There are three sign-in methods:
- Email and password
- Emailed sign-in link, valid for 15 minutes and rate limited
If you signed up with Google, your account has no ChartInspect password. Settings shows a "Google Account Linked" badge instead of "Password Protected", there is no Change Password button, and password recovery does not apply.
Two-Factor Authentication (2FA)
What it is
2FA adds a second factor to sign-in: your password plus a rotating code from an authenticator app. ChartInspect uses TOTP only, there is no SMS or emailed-code 2FA.
Setting up 2FA
- Go to Settings > Login & Security
- Under Two-Factor Authentication, click Enable 2FA
- Scan the QR code with an authenticator app (Google Authenticator, Authy, Microsoft Authenticator, or any TOTP app), or use the manual entry key
- Enter the 6-digit code
- Save your backup codes, they are shown exactly once
Codes from roughly one minute either side of the current step are accepted, so a slightly out-of-sync clock will not lock you out.
Backup codes
Enabling 2FA issues 10 backup codes, each 8 characters, stored hashed on our side. Each code works once and is consumed when used.
- Store them somewhere safe and offline
- Settings shows how many remain, never the codes themselves
- You can regenerate them from Regenerate Backup Codes in Login & Security, which issues a fresh set of 10 and invalidates the old ones
Signing in with a backup code
On the verification screen, click Use a backup code instead and enter one.
If you lose your authenticator and your backup codes
- On the verification screen click Lost access to authenticator & backup codes?, or go to 2FA recovery
- Enter your account email. We send a recovery link, valid for one hour
- Open it and click Disable 2FA
- Sign in normally, then re-enable 2FA from Settings
This requires access to the account's email inbox. Contact support only if you no longer control that inbox.
Disabling 2FA
- Go to Settings > Login & Security
- Click Disable 2FA
- Confirm with your account password (Google sign-in accounts simply confirm)
ChartInspect emails you whenever 2FA is enabled, disabled, or recovery is requested, so an unexpected message is worth investigating.
Password Security
Enforced requirements
At least 8 characters, including at least one lowercase letter, one uppercase letter and one number. Symbols are allowed but not required.
Recommended
- A unique password used nowhere else
- Longer than the minimum, 12 characters or more
- Stored in a password manager
Changing your password
Go to Settings > Login & Security and click Change Password under Authentication Methods. Google sign-in accounts do not have this option; manage that account with Google.
Resetting a forgotten password
Use the "Forgot password" link on the sign-in page. The emailed reset link expires after one hour.
Sessions
Sign-in sessions last 30 days, or 90 days if you choose Remember Me.
Login & Security shows a Security Score plus a Recent Activity block with your Last Login and, if 2FA is on, Last 2FA Used.
To end a session, use Sign Out at the bottom of the Settings sidebar. Note that this signs out the current device only. There is no remote sign-out, and changing your password does not end sessions on other devices, so if you suspect your account is compromised, contact support.
API Keys
Create and revoke API keys at Settings > API Access.
- The secret is shown once, at creation, and is never recoverable
- Free accounts can hold 3 active keys, Pro 10
- Revoking is immediate
- A key's tier is resolved live from your subscription, so a lapsed Pro key drops back to free limits automatically
Treat keys like passwords: never commit them, and revoke and re-create rather than sharing one.
Account Deletion
Account deletion is handled by our team rather than a self-serve button. Email [email protected] from the account's email address, from Settings > Danger Zone. Requests are processed within 30 days.
If Your Account Is Compromised
- Change your password immediately, or set one if you sign in with Google
- Enable 2FA if it is not already on, and regenerate backup codes
- Revoke every API key at Settings > API Access
- Review your alerts and notification destinations
- Contact support, since sessions on other devices cannot be revoked from the UI