Secure your account: two-step verification and signed-in devices
Add an authenticator code to sign-in, see every device that is signed in, and sign out the ones you don’t recognise.
- Plan
- Every plan
- Updated
On this page
Turn on two-step verificationLink to “Turn on two-step verification”
- In Settings, find “Two-step verification” and choose “Turn on two-step verification”.
- Confirm your password, then scan the QR code with an authenticator app, or type the key in by hand.
- Enter the code your app shows and choose “Confirm and turn on”.
- “Save your backup codes” comes next. Each code works once, and they are shown only this one time.
Turning it on asks for your password. If you signed up with Google or a sign-in link and have no password yet, use “Add a password” first. If you lose your phone, the sign-in page offers “Lost your phone? Use a backup code”.
See and sign out devicesLink to “See and sign out devices”
- “Signed-in devices” lists each browser with its IP address, when it was last active, and when it signed in. The one you are using is marked “This device”.
- Sign any one of them out, or choose “Sign out all other devices”.
- Changing your password under “Change password” also signs out every other device.
- You stay signed in while you use PaloWorks; a session left unused for 7 days expires.
PasskeysLink to “Passkeys”
Under “Passkeys”, choose “Add a passkey” to sign in with Face ID, Touch ID, Windows Hello, or a security key instead of a password. A passkey only works on this site, so a look-alike phishing page cannot use it.
Require it for your whole teamLink to “Require it for your whole team”
The workspace owner can tick “Require two-step verification” in Settings → Team. Anyone in the workspace without it — the owner included — sees a prompt to set it up instead of clients, projects and invoices; Settings stays open so they can. The owner has to turn it on for their own account first.
Security emailLink to “Security email”
You get an email when your password is changed or reset, and when your account is signed in from a new kind of device while another device is already signed in. These always send, whatever your notification settings say.
Other ways to sign inLink to “Other ways to sign in”
- “Email me a sign-in link” on the login page sends a link that works once and expires after 10 minutes.
- A password reset link expires after an hour, and using it signs out every session.
- To change the email address on your account, write to support@paloworks.com.
Found a security problem in PaloWorks itself? How to report it is in the Privacy Policy.
Related articles
- Account and securityExport your data or close your accountDownload everything in your workspace as JSON, or close the account and have its data deleted.
- Account and securityChoose your email: alerts, the weekly digest, and read receiptsSix switches decide which optional email you get; invoices, receipts, and sign-in email always send.
Still stuck?
Write to support@paloworks.com. A person who builds PaloWorks reads it and answers.
Other ways to reach us are on the contact page.