Your account & security
Click Manage account (or your name) at the bottom of the sidebar to open
your account settings — a sectioned page with Profile, Preferences,
Notifications, Security, and API tokens in a left-hand rail.
Each section has its own URL, so links like /account/security land exactly
where you expect.
Profile
Section titled “Profile”Your display name, email, and an optional profile photo (it’s resized in your browser before upload; your initials remain the fallback everywhere a photo isn’t set). Usernames are permanent — they anchor history, comments, and sign-in.
Preferences
Section titled “Preferences”- Theme — Light, Dark, or Auto. Saved to your account, so it follows you to any browser you sign in from; the sidebar toggle writes through to the same setting.
- Page width — Normal / Wide / Full (Wide is the default), applied app-wide, settings pages included. The same toggle appears at the top of every document. Document body text keeps a readable column inside whichever width you pick — and the column grows as you widen the page, so Full gives you longer lines than Normal without ever running edge to edge. Panels and media — tables, code blocks, diagrams, images, callouts, accordions, tabs, video and embeds — use the full width at every setting.
- Time zone & date format — personal overrides of the workspace defaults. Every timestamp in the app follows them — documents, history, the audit log, analytics, account security, the dashboard — and the weekly digest arrives Monday morning in your time zone, formatted your way.
Notifications
Section titled “Notifications”What reaches you where — a per-event grid covering mentions, comment replies, subscribed-space updates, change requests, review decisions, review reminders, and read confirmations, each with its own in-app, webhook, and (where an email exists) email switch. Everything is on by default; unchecking stores a personal opt-out. Subscription emails and the weekly digest keep their own master switches below the grid, next to your personal chat webhook and subscribed-spaces list.
Two-factor authentication (2FA)
Section titled “Two-factor authentication (2FA)”Add an authenticator-app code to your password sign-in (Manage account → Security → Set up two-factor auth):
- Scan the QR code with any TOTP app — 1Password, Google Authenticator, Microsoft Authenticator, Authy… (or type the manual key).
- Enter the 6-digit code it shows to confirm the app works. 2FA is only enforced after this succeeds, so a bad scan can’t lock you out.
- Save the recovery codes — eight one-time codes, shown exactly once. Any of them signs you in if you lose your authenticator (each works once).
From then on, password sign-ins ask for your current 6-digit code (or a recovery code) after the password. Turning 2FA off again requires a valid code.
Locked out?
Section titled “Locked out?”- Lost authenticator, have recovery codes → sign in with a recovery code, turn 2FA off under Security, re-enroll with the new device.
- Lost both → an admin can clear your 2FA from Settings → Users & roles → Reset 2FA; you sign in with just your password and re-enroll. The reset is written to the audit log.
Active sessions
Section titled “Active sessions”Manage account → Security → Active sessions lists every device where you’re signed in — browser and OS, IP address, and when it signed in, with your current device marked. You can:
- Sign out any single session, or
- Sign out everywhere else — instantly revokes every session except the one you’re using. Do this if you signed in on a shared machine or lost a device.
Admin password resets also revoke all of a user’s sessions automatically.
Passwords & API tokens
Section titled “Passwords & API tokens”- Change password — at the top of the Security section.
- API tokens & connected apps — personal tokens for the Claude connector and other integrations, plus the one-click apps you’ve approved. Both revocable anytime.
