For the complete documentation index, see llms.txt. This page is also available as Markdown.

Authentication and account recovery

Protect human accounts and recovery paths.

Account controls protect the entry point to every workspace, project, source, model, and release a user can access. Use organization-owned identities and a recovery process that does not depend on one unavailable person.

Account security page showing password and 2FA status

Open Personal Settings › Account security. Unitlab identifies whether two-factor authentication is enabled and explains that sign-in will require a six-digit code from a TOTP-compatible authenticator app.

Unitlab supports email/password sign-up and sign-in, Google authentication, email verification, invitation-token access, password reset, and TOTP two-factor authentication.

Two-factor authentication includes QR/secret setup, verification, ten single-use backup codes shown once, login challenge, disable, and backup-code regeneration. When 2FA is enabled, password change, password-reset completion, account deletion, and workspace destruction require an appropriate second factor.

If a user refreshes during the temporary 2FA login challenge, the challenge is cleared and the user returns to login rather than leaving reusable sensitive state in the browser.

Use this in production

  • Require verified organization-owned email addresses and strong unique credentials according to policy.

  • To enable 2FA, choose Enable 2FA, scan the QR code or enter the setup key in an approved TOTP authenticator, choose Next, and verify the generated six-digit code.

  • Never capture, publish, or paste the QR code, setup key, one-time code, password, or recovery material.

  • Test the next sign-in and retain approved recovery information outside tickets and public documentation.

  • Keep at least two accountable workspace owners where policy permits so account recovery does not depend on one person.

  • Investigate unexpected sign-in, recovery, or notification activity promptly and rotate affected passwords, API keys, and connected credentials.


Explore related Unitlab capabilities: Unitlab’s data annotation platform