Authentication and account recovery
Protect human accounts and recovery paths.
Account controls protect the entry point to every workspace, project, source, model, and release a user can access. Use organization-owned identities and a recovery process that does not depend on one unavailable person.

Open Personal Settings › Account security. Unitlab identifies whether two-factor authentication is enabled and explains that sign-in will require a six-digit code from a TOTP-compatible authenticator app.
Unitlab supports email/password sign-up and sign-in, Google authentication, email verification, invitation-token access, password reset, and TOTP two-factor authentication.
Two-factor authentication includes QR/secret setup, verification, ten single-use backup codes shown once, login challenge, disable, and backup-code regeneration. When 2FA is enabled, password change, password-reset completion, account deletion, and workspace destruction require an appropriate second factor.
If a user refreshes during the temporary 2FA login challenge, the challenge is cleared and the user returns to login rather than leaving reusable sensitive state in the browser.
Use this in production
Require verified organization-owned email addresses and strong unique credentials according to policy.
To enable 2FA, choose Enable 2FA, scan the QR code or enter the setup key in an approved TOTP authenticator, choose Next, and verify the generated six-digit code.
Never capture, publish, or paste the QR code, setup key, one-time code, password, or recovery material.
Test the next sign-in and retain approved recovery information outside tickets and public documentation.
Keep at least two accountable workspace owners where policy permits so account recovery does not depend on one person.
Investigate unexpected sign-in, recovery, or notification activity promptly and rotate affected passwords, API keys, and connected credentials.
Explore related Unitlab capabilities: Unitlab’s data annotation platform