> For the complete documentation index, see [llms.txt](https://docs.unitlab.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.unitlab.ai/documentation/security/authentication-and-account-recovery.md).

# Authentication and account recovery

Account controls protect the entry point to every workspace, project, source, model, and release a user can access. Use organization-owned identities and a recovery process that does not depend on one unavailable person.

![Account security page showing password and 2FA status](https://292810646-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FGjVLUz4wthGkGlRKM6rM%2Fuploads%2FJrstdUsQmqNdGlH4P2Mp%2Faccount-security.png?alt=media\&token=8a678b4a-9d4c-463b-b462-17986926e8fa)

*Open Personal Settings › Account security. Unitlab identifies whether two-factor authentication is enabled and explains that sign-in will require a six-digit code from a TOTP-compatible authenticator app.*

Unitlab supports email/password sign-up and sign-in, Google authentication, email verification, invitation-token access, password reset, and TOTP two-factor authentication.

Two-factor authentication includes QR/secret setup, verification, ten single-use backup codes shown once, login challenge, disable, and backup-code regeneration. When 2FA is enabled, password change, password-reset completion, account deletion, and workspace destruction require an appropriate second factor.

If a user refreshes during the temporary 2FA login challenge, the challenge is cleared and the user returns to login rather than leaving reusable sensitive state in the browser.

### Use this in production

* Require verified organization-owned email addresses and strong unique credentials according to policy.
* To enable 2FA, choose Enable 2FA, scan the QR code or enter the setup key in an approved TOTP authenticator, choose Next, and verify the generated six-digit code.
* Never capture, publish, or paste the QR code, setup key, one-time code, password, or recovery material.
* Test the next sign-in and retain approved recovery information outside tickets and public documentation.
* Keep at least two accountable workspace owners where policy permits so account recovery does not depend on one person.
* Investigate unexpected sign-in, recovery, or notification activity promptly and rotate affected passwords, API keys, and connected credentials.
