Skip to content

Your account & security

Click Manage account (or your name) at the bottom of the sidebar to open your account settings — a sectioned page with Profile, Preferences, Notifications, Security, and API tokens in a left-hand rail. Each section has its own URL, so links like /account/security land exactly where you expect.

Your display name, email, and an optional profile photo (it’s resized in your browser before upload; your initials remain the fallback everywhere a photo isn’t set). Usernames are permanent — they anchor history, comments, and sign-in.

  • Theme — Light, Dark, or Auto. Saved to your account, so it follows you to any browser you sign in from; the sidebar toggle writes through to the same setting.
  • Page width — Normal / Wide / Full (Wide is the default), applied app-wide, settings pages included. The same toggle appears at the top of every document. Document body text keeps a readable column inside whichever width you pick — and the column grows as you widen the page, so Full gives you longer lines than Normal without ever running edge to edge. Panels and media — tables, code blocks, diagrams, images, callouts, accordions, tabs, video and embeds — use the full width at every setting.
  • Time zone & date format — personal overrides of the workspace defaults. Every timestamp in the app follows them — documents, history, the audit log, analytics, account security, the dashboard — and the weekly digest arrives Monday morning in your time zone, formatted your way.

What reaches you where — a per-event grid covering mentions, comment replies, subscribed-space updates, change requests, review decisions, review reminders, and read confirmations, each with its own in-app, webhook, and (where an email exists) email switch. Everything is on by default; unchecking stores a personal opt-out. Subscription emails and the weekly digest keep their own master switches below the grid, next to your personal chat webhook and subscribed-spaces list.

Add an authenticator-app code to your password sign-in (Manage account → Security → Set up two-factor auth):

  1. Scan the QR code with any TOTP app — 1Password, Google Authenticator, Microsoft Authenticator, Authy… (or type the manual key).
  2. Enter the 6-digit code it shows to confirm the app works. 2FA is only enforced after this succeeds, so a bad scan can’t lock you out.
  3. Save the recovery codes — eight one-time codes, shown exactly once. Any of them signs you in if you lose your authenticator (each works once).

From then on, password sign-ins ask for your current 6-digit code (or a recovery code) after the password. Turning 2FA off again requires a valid code.

  • Lost authenticator, have recovery codes → sign in with a recovery code, turn 2FA off under Security, re-enroll with the new device.
  • Lost both → an admin can clear your 2FA from Settings → Users & roles → Reset 2FA; you sign in with just your password and re-enroll. The reset is written to the audit log.

Manage account → Security → Active sessions lists every device where you’re signed in — browser and OS, IP address, and when it signed in, with your current device marked. You can:

  • Sign out any single session, or
  • Sign out everywhere else — instantly revokes every session except the one you’re using. Do this if you signed in on a shared machine or lost a device.

Admin password resets also revoke all of a user’s sessions automatically.

  • Change password — at the top of the Security section.
  • API tokens & connected apps — personal tokens for the Claude connector and other integrations, plus the one-click apps you’ve approved. Both revocable anytime.