Supportaccount

account

Account Security & Two-Factor Authentication

Enable TOTP two-factor authentication, manage backup codes, recover a locked account, and handle API keys safely.

Updated 2026-08-154 min read#security #2fa #password

How You Sign In

There are three sign-in methods:

  • Email and password
  • Google
  • Emailed sign-in link, valid for 15 minutes and rate limited

If you signed up with Google, your account has no ChartInspect password. Settings shows a "Google Account Linked" badge instead of "Password Protected", there is no Change Password button, and password recovery does not apply.

Two-Factor Authentication (2FA)

What it is

2FA adds a second factor to sign-in: your password plus a rotating code from an authenticator app. ChartInspect uses TOTP only, there is no SMS or emailed-code 2FA.

Setting up 2FA

  1. Go to Settings > Login & Security
  2. Under Two-Factor Authentication, click Enable 2FA
  3. Scan the QR code with an authenticator app (Google Authenticator, Authy, Microsoft Authenticator, or any TOTP app), or use the manual entry key
  4. Enter the 6-digit code
  5. Save your backup codes, they are shown exactly once

Codes from roughly one minute either side of the current step are accepted, so a slightly out-of-sync clock will not lock you out.

Backup codes

Enabling 2FA issues 10 backup codes, each 8 characters, stored hashed on our side. Each code works once and is consumed when used.

  • Store them somewhere safe and offline
  • Settings shows how many remain, never the codes themselves
  • You can regenerate them from Regenerate Backup Codes in Login & Security, which issues a fresh set of 10 and invalidates the old ones

Signing in with a backup code

On the verification screen, click Use a backup code instead and enter one.

If you lose your authenticator and your backup codes

  1. On the verification screen click Lost access to authenticator & backup codes?, or go to 2FA recovery
  2. Enter your account email. We send a recovery link, valid for one hour
  3. Open it and click Disable 2FA
  4. Sign in normally, then re-enable 2FA from Settings

This requires access to the account's email inbox. Contact support only if you no longer control that inbox.

Disabling 2FA

  1. Go to Settings > Login & Security
  2. Click Disable 2FA
  3. Confirm with your account password (Google sign-in accounts simply confirm)

ChartInspect emails you whenever 2FA is enabled, disabled, or recovery is requested, so an unexpected message is worth investigating.

Password Security

Enforced requirements

At least 8 characters, including at least one lowercase letter, one uppercase letter and one number. Symbols are allowed but not required.

Recommended

  • A unique password used nowhere else
  • Longer than the minimum, 12 characters or more
  • Stored in a password manager

Changing your password

Go to Settings > Login & Security and click Change Password under Authentication Methods. Google sign-in accounts do not have this option; manage that account with Google.

Resetting a forgotten password

Use the "Forgot password" link on the sign-in page. The emailed reset link expires after one hour.

Sessions

Sign-in sessions last 30 days, or 90 days if you choose Remember Me.

Login & Security shows a Security Score plus a Recent Activity block with your Last Login and, if 2FA is on, Last 2FA Used.

To end a session, use Sign Out at the bottom of the Settings sidebar. Note that this signs out the current device only. There is no remote sign-out, and changing your password does not end sessions on other devices, so if you suspect your account is compromised, contact support.

API Keys

Create and revoke API keys at Settings > API Access.

  • The secret is shown once, at creation, and is never recoverable
  • Free accounts can hold 3 active keys, Pro 10
  • Revoking is immediate
  • A key's tier is resolved live from your subscription, so a lapsed Pro key drops back to free limits automatically

Treat keys like passwords: never commit them, and revoke and re-create rather than sharing one.

Account Deletion

Account deletion is handled by our team rather than a self-serve button. Email [email protected] from the account's email address, from Settings > Danger Zone. Requests are processed within 30 days.

If Your Account Is Compromised

  1. Change your password immediately, or set one if you sign in with Google
  2. Enable 2FA if it is not already on, and regenerate backup codes
  3. Revoke every API key at Settings > API Access
  4. Review your alerts and notification destinations
  5. Contact support, since sessions on other devices cannot be revoked from the UI

Was this article helpful?

Your feedback helps us improve the support library.

Still need help?

Contact the support team with the article title and your question.

Contact support