Account security

Two-step verification, passkeys and remembered devices: how your access to Hilbana is protected.

Your account can be protected two ways, and they’re not exclusive: passkeys (sign in without a password) and two-step verification (a code on top of the password). Both live in Settings → Profile.

Passkeys

A passkey lets you sign in with your device’s fingerprint, face or PIN, without typing the password.

  • Add passkey registers the device you’re on; you can have several (laptop, phone…) and rename them.
  • You can see when each one was last used.
  • Deleting one needs your password, and it signs out your other open sessions. Note: that unlinks it from Hilbana, but the key is still stored on your device — delete it there too or it will keep being offered at sign-in.
  • It needs a supported browser; if yours isn’t, the app says so.

Two-step verification

Asks for a 6-digit code from your authenticator app (TOTP) at sign-in, on top of the password.

  • Turning it on means scanning a QR (or copying the key by hand) and confirming with a code and your password.
  • You get single-use recovery codes, to get in if you lose your phone. They are never shown again: save them. You can regenerate them at any time — the old ones stop working.
  • Remembered devices: a trusted device can skip the code, and you can revoke them (one or all) from the same screen.
  • Turning it off requires your password.

“Protect your account”

If you sign in with neither a passkey nor two-step verification, Hilbana shows a screen suggesting you turn one on. It can be postponed: it’s a reminder, not a block.

What gets recorded

Sign-in attempts and security changes (login, failed login, code verified or failed, passkeys added and removed, 2FA enabled and disabled, password changes) are written to the workspace audit log.

Related: Profile · Audit log · Members & roles.