Account security
On this page
Open Account Settings from your account menu. Profile contains your name, photo, title, and theme. Sign-in & security contains your sign-in methods, passkeys, two-factor preference, and recovery options.
Profile edits and the account MFA preference use Save and Discard at the top of their pages. Actions such as changing a password or adding a passkey save in their own dialogs.
Add and manage passkeys
A passkey lets you sign in with your fingerprint, face, or device PIN, using your device or password manager. It provides MFA without a separate code. Your organization must allow passkeys for you to use one to access that organization.
- Open Sign-in & security. If your email is not verified, click Verify email and complete the email link first.
- Under Passkeys, click Add passkey.
- Give it a name you will recognize, such as Work laptop.
- Complete any identity verification Specset requests, then follow your browser or password manager's passkey prompt.
- Confirm that the passkey appears in your list. On your next sign-in, enter your email and choose Use a passkey when offered.
Use the Rename or Remove button beside a passkey to manage it. Removing a passkey signs out sessions that rely on it. Keep another permitted way to sign in before removing an authenticator.
If you use a passkey for an organization requiring phishing-resistant MFA, it must be an approved passkey. Contact Specset support through your administrator if setup asks for approval. An enrolled passkey does not replace SSO when an organization requires SSO.
Require MFA for your own sign-ins
After adding a passkey, you can enable Require MFA when signing in without SSO and click Save. This applies to your personal account's non-SSO sign-ins. It does not turn on MFA for everyone in an organization or replace the organization's own requirements.
Authenticator app codes are not yet available in production. The settings page may show the option or an unavailable message. Enabling an organization setting does not enable authenticator-app setup. Use a permitted passkey, or your organization's qualifying SSO route, for stronger authentication.
For team-wide settings, see Organization security.
Change your password
- Under Sign-in methods, click Change password or Set password.
- Verify your identity if prompted, then complete the password form.
- Choose a unique passphrase of at least 15 characters. Specset checks new passwords against common passwords and account information, and shows any length or size limits in the form.
- Click Update.
Use Forgot your password? on the sign-in page if you cannot remember your password. Resetting it does not remove MFA or your organization's SSO requirements; return to sign-in after completing the reset.
Verify or change your email
Click Verify email if your address is unverified. To change it, click Change email, complete identity verification, and confirm the new address using the email link in the same browser while signed in. The old address remains on your account until confirmation is complete. Both addresses receive a notice about the change.
If your account requires an administrator-managed process, contact Specset support through your administrator.
Recover access
Recovery codes are available to eligible accounts with an enrolled authenticator and a usable password sign-in method.
- Under Account recovery, click Generate codes and complete verification if prompted.
- Store the codes securely before closing the dialog. They are shown once, and generating a new set replaces the old set.
- If you lose access to your authenticator, choose Use a recovery code on the sign-in page and enter your password and one unused code.
- Complete the replacement-authenticator setup. A recovery code does not grant access until that setup and verification finish.
Accounts with stronger protection use administrator-assisted recovery instead. If your organizations require SSO, use your identity provider's recovery process and contact your administrator when necessary.
Why Specset asks you to verify again
Changing credentials, your email, recovery options, or an MFA preference requires recent authentication that meets your account's requirements. Specset asks for verification as part of the action when needed. You do not need to visit a separate verification page first.
If verification expires or you cancel, your change is not applied. Follow the dialog to retry, or return when you have access to a permitted method. To connect an existing Google Workspace account, see Single sign-on.