Skip to main content

Account security

The Security section shows the effective protection state of the selected master account: email confirmation, enrolled two-factor methods, recovery codes, and passkeys.

Protection methods and registered passkeys

Review order​

  1. Verify the email address and its confirmation state.
  2. Check which 2FA methods are actually enabled.
  3. Review active and already disabled passkeys.
  4. Compare the request with sessions, IP activity, and the activity timeline.
  5. Reset protection only after completing the accepted owner-verification procedure.

Password and recovery​

Changing a password and sending account recovery are separate operations. An administrative change sets a new value and requires a reason; recovery sends the standard player flow without exposing a new password to the operator.

New password, confirmation, and the reason for the sensitive operation
Confirmation for sending the standard account-recovery flow

PIN and sign-in protection​

The PIN can be replaced or cleared. Clearing requires a separate confirmation because it removes an active protection factor. Shield state has its own form and is not a substitute for changing the password.

New PIN and the required administrative reason
Separate confirmation for removing the active PIN
Managing the additional sign-in protection state

2FA and passkeys​

Disabling one 2FA method does not affect the others. A full reset removes every active method and recovery code and is reserved for account recovery. Revoking a passkey prevents future sign-ins with that key while retaining its record and disabled date.

Targeted removal of the selected 2FA method with a reason
Confirmation for removing all 2FA methods and recovery codes
Revoking one passkey while keeping its audit record

Passkey revocation, 2FA reset, and session termination require a reason. After confirmation, the updated state appears in the same table.

warning

Do not disable protection only to bypass a sign-in error. Review account status, recent sessions, and account-takeover signals first.