Account security
Login credentials, recovery keys, MFA, passkeys, anti-phishing codes, inactivity lock, forced password change for org/enterprise invites, email changes, and self-service account deletion. The full security surface for an Aden user account.
What it is
Your Aden account has several layers of protection: a password (or OAuth via Google/Spotify), optional two-factor authentication (TOTP or passkey), an anti-phishing code embedded in every email Aden sends you, and an inactivity lock that can require a PIN after a period of idle time.
You can also change the email address on your account, and you can permanently delete your account when you no longer need it.
Using it
Change your password. Go to Account → Password. Enter your current password and then your new one twice. Password changes clear the MFA-verified session cookie so you'll be prompted to re-verify on the next protected action.
Back up a recovery key. Right after signing up you'll see a one-time Back up your recovery key screen with twelve words. Download and continue saves them as a text file and moves you on; you can copy or print them instead. If you ever forget your password, even without access to your email. Go to the login page, choose Use your recovery key, and enter your email, the twelve words, and a new password. You can view your key's status or generate a fresh one any time under Account → Password. Aden only stores an encrypted hash of the words, so if you lose them we can't recover them for you. Generate a new key instead.
Set up two-factor authentication. Go to Account → MFA. Scan the QR code with an authenticator app (Google Authenticator, 1Password, etc.) and enter the six-digit code to confirm. On a phone, where there is no second screen to scan: tap Add to authenticator app instead and the account is handed straight to the app you have installed. From then on, signing in from a new session triggers a second prompt. You can also unenrol from the same page.
Get your code without app-hunting. On the verification screen, phones show an Open authenticator app button. Pick your app once (Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden) and every later login opens it in one tap. If nothing opens, Aden says so and reopens the list so you can pick another app.
Paste the code instead of typing it. Copy the code in your authenticator app, come back, and tap Paste code: Aden picks the six digits out of the clipboard and verifies straight away. The code boxes turn green when the code is accepted and red, with the reason, when it isn't.
Add a passkey. Under Account → Login methods you can register a device passkey (Face ID, Touch ID, Windows Hello). Passkeys replace the password step when signing in on that device.
Set an anti-phishing code. Go to Account → Security and choose a
4–20-character personal code (e.g. sunshine42). Aden will include it in every
transactional email so you can instantly spot real messages from fakes.
Enable inactivity lock. Under Account → Security, turn on the inactivity lock and choose a timeout (1–480 minutes). After that idle period, reopening the app asks for your PIN (or biometrics if enabled). Team admins can also require inactivity lock for all members from Team settings → Security.
Change your email address. Go to Account → Security, enter a new address, and confirm both the old and new address via the links Aden sends. The change only takes effect after both confirmations. Once you submit, Aden shows a one-click Open Gmail / Outlook / … button that takes you straight to your new inbox with a search for our email already filled in, no hunting through your mail.
Delete your account. Go to Account → Delete. The page checks whether you are the sole admin or sole member of any team, if so, you'll need to transfer those teams first. Once all blockers are cleared, confirm deletion. Your profile row is kept as a tombstone so collaborator credits on tracks and comments remain, but you can no longer sign in.