Account security
Passkeys and two-factor authentication for your dashboard account.
Your account is what signs in to the dashboard, across every organization you belong to. Open Account at the bottom of the sidebar to manage how you prove it is you.
Passkeys
A passkey signs you in with your fingerprint, face or device PIN instead of a password.
It is stored by your device or password manager and bound to app.carillon.dev.
Add a passkey. On the account page, choose Add a passkey, give it a name you will recognise in the list, and follow your browser's prompt. The passkey appears in the list with the date it was added.
Sign in with it. On the sign-in page, choose Sign in with a passkey and complete your browser's prompt. A passkey sign-in is not asked for a two-factor code: the device and what unlocked it are already two factors.
Remove a passkey. Choose Remove next to it. If it was the last one, you sign in with your password.
Passkeys need a browser that supports WebAuthn. The account page says so when the current browser does not.
Two-factor authentication
With two-factor authentication on, every password sign-in also asks for a six-digit code from an authenticator app.
Turn it on.
- On the account page, choose Turn on and confirm your password.
- Scan the QR code with your authenticator app, or enter the key by hand.
- Enter the code the app shows. The account is protected only once this code is accepted.
- Save the ten backup codes. They are shown once.
Sign in. Enter your email and password as usual, then the code from the app. Check Trust this browser for 30 days to skip the code on that browser until then.
Lost the authenticator. Choose Use a backup code instead on the code page. Each backup code works once. Make a new set from the account page with New backup codes, which invalidates the previous ones.
Turn it off. Choose Turn off and confirm your password. Your password alone signs you in again, and the backup codes stop working.
Too many wrong codes lock the account for a few minutes; sign in again afterwards.
What still applies
- The CLI signs in through device approval in the browser, so a passkey or a two-factor code is asked there, not in the terminal.
- Agents connecting through MCP sign in on the same page, with the same steps.
- Invitations to an organization are accepted after signing in, with the same steps.