Account security
Two-step verification, passkeys and remembered devices: how your access to Hilbana is protected.
Your account can be protected two ways, and they’re not exclusive: passkeys (sign in without a password) and two-step verification (a code on top of the password). Both live in Settings → Profile.
Passkeys
A passkey lets you sign in with your device’s fingerprint, face or PIN, without typing the password.
- Add passkey registers the device you’re on; you can have several (laptop, phone…) and rename them.
- You can see when each one was last used.
- Deleting one needs your password, and it signs out your other open sessions. Note: that unlinks it from Hilbana, but the key is still stored on your device — delete it there too or it will keep being offered at sign-in.
- It needs a supported browser; if yours isn’t, the app says so.
Two-step verification
Asks for a 6-digit code from your authenticator app (TOTP) at sign-in, on top of the password.
- Turning it on means scanning a QR (or copying the key by hand) and confirming with a code and your password.
- You get single-use recovery codes, to get in if you lose your phone. They are never shown again: save them. You can regenerate them at any time — the old ones stop working.
- Remembered devices: a trusted device can skip the code, and you can revoke them (one or all) from the same screen.
- Turning it off requires your password.
“Protect your account”
If you sign in with neither a passkey nor two-step verification, Hilbana shows a screen suggesting you turn one on. It can be postponed: it’s a reminder, not a block.
What gets recorded
Sign-in attempts and security changes (login, failed login, code verified or failed, passkeys added and removed, 2FA enabled and disabled, password changes) are written to the workspace audit log.
Related: Profile · Audit log · Members & roles.