# Account security
Source: https://docs.aden.space/docs/help/get-started/account-security

Login credentials, recovery keys, MFA, passkeys, anti-phishing codes, inactivity lock, forced password change for org/enterprise invites, email changes, and self-service account deletion. The full security surface for an Aden user account.
{/* Generated by `bun docs:publish` from docs/features/account-security.md: edit the spec, not this file. */}

## What it is [#what-it-is]

Your Aden account has several layers of protection: a password (or OAuth via
Google/Spotify), optional two-factor authentication (TOTP or passkey), an
anti-phishing code embedded in every email Aden sends you, and an inactivity
lock that can require a PIN after a period of idle time.

You can also change the email address on your account, and you can permanently
delete your account when you no longer need it.

## Using it [#using-it]

**Change your password.** Go to **Account → Password**. Enter your current
password and then your new one twice. Password changes clear the MFA-verified
session cookie so you'll be prompted to re-verify on the next protected action.

**Back up a recovery key.** Right after signing up you'll see a one-time
**Back up your recovery key** screen with twelve words. **Download and
continue** saves them as a text file and moves you on; you can copy or print
them instead. If you ever forget your password, even
without access to your email. Go to the login page, choose **Use your
recovery key**, and enter your email, the twelve words, and a new password.
You can view your key's status or generate a fresh one any time under
**Account → Password**. Aden only stores an encrypted hash of the words, so
if you lose them we can't recover them for you. Generate a new key instead.

**Set up two-factor authentication.** Go to **Account → MFA**. Scan the QR
code with an authenticator app (Google Authenticator, 1Password, etc.) and
enter the six-digit code to confirm. On a phone, where there is no second
screen to scan: tap **Add to authenticator app** instead and the account is
handed straight to the app you have installed. From then on, signing in from a
new session triggers a second prompt. You can also unenrol from the same page.

**Get your code without app-hunting.** On the verification screen, phones show
an **Open authenticator app** button. Pick your app once (Google
Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden) and every
later login opens it in one tap. If nothing opens, Aden says so and reopens the
list so you can pick another app.

**Paste the code instead of typing it.** Copy the code in your authenticator
app, come back, and tap **Paste code**: Aden picks the six digits out of the
clipboard and verifies straight away. The code boxes turn green when the code
is accepted and red, with the reason, when it isn't.

**Add a passkey.** Under **Account → Login methods** you can register
a device passkey (Face ID, Touch ID, Windows Hello). Passkeys replace the
password step when signing in on that device.

**Set an anti-phishing code.** Go to **Account → Security** and choose a
4–20-character personal code (e.g. `sunshine42`). Aden will include it in every
transactional email so you can instantly spot real messages from fakes.

**Enable inactivity lock.** Under **Account → Security**, turn on the
inactivity lock and choose a timeout (1–480 minutes). After that idle period,
reopening the app asks for your PIN (or biometrics if enabled). Team admins can
also require inactivity lock for all members from **Team settings → Security**.

**Change your email address.** Go to **Account → Security**, enter a new
address, and confirm both the old and new address via the links Aden sends. The
change only takes effect after both confirmations. Once you submit, Aden shows a
one-click &#x2A;*Open Gmail / Outlook / …** button that takes you straight to your new
inbox with a search for our email already filled in, no hunting through your
mail.

**Delete your account.** Go to **Account → Delete**. The page checks whether
you are the sole admin or sole member of any team, if so, you'll need to
transfer those teams first. Once all blockers are cleared, confirm deletion.
Your profile row is kept as a tombstone so collaborator credits on tracks and
comments remain, but you can no longer sign in.