> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kugelaudio.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Account security

> Protect your KugelAudio account with two-factor authentication and passkeys

Two features protect the account you use to sign in to the
[KugelAudio dashboard](https://kugelaudio.com/dashboard):

* **Two-factor authentication (2FA)** asks for a six-digit code from an
  authenticator app after your password or single sign-on.
* **Passkeys** let you sign in with your device's fingerprint, face, PIN or a
  security key instead of a password.

Both are optional for each person, unless an admin of your organization
requires 2FA. API keys are separate credentials; they are covered in
[Authentication](/api-reference/authentication).

## Set up two-factor authentication

You need an authenticator app such as Google Authenticator, Microsoft
Authenticator, 1Password or Authy. KugelAudio does not send codes by SMS.

1. In the dashboard sidebar, open **Team & Settings**, then **Account Settings**.
2. In the security section, choose to add an authenticator app.
3. Scan the QR code with your authenticator app, or type in the setup key shown
   below it.
4. Enter the six-digit code your app shows to confirm.

From then on, every sign-in asks for a current code from the app. You can
remove the authenticator app from the same page.

## Sign in with a passkey

1. Sign in as usual, then open **Account Settings** and add a passkey. Your
   browser or password manager asks you to confirm with your fingerprint, face,
   PIN or security key.
2. Next time, open the sign-in page. Your browser offers your passkey in the
   email field right away; pick it and confirm on your device. No password is
   needed. If your browser does not offer it, sign in with your email and
   password as usual.

A passkey counts as two factors on its own: it proves you hold the device and
confirms you with your fingerprint, face or PIN. After a passkey sign-in,
KugelAudio does not ask for your authenticator code, and it opens organizations
that require 2FA. Adding or removing a passkey or an authenticator app, and
changing your password, still ask for your authenticator code if you have one.

## When your organization requires 2FA

Organization owners and admins can require 2FA for everyone in the organization
under **Team & Settings**, then **Organization Settings**. The same page shows
which members already have 2FA set up.

* To turn the requirement on, the admin must have 2FA set up and have signed in
  with it, so an admin cannot lock themselves out.
* A member without 2FA is asked to set it up the next time they open the
  organization, and gets access once it is done.
* A member with 2FA who signed in with a password or single sign-on is asked
  for their code before the organization opens. Signing in with a passkey
  counts as 2FA, so no code is needed.

The requirement applies to one organization. Your other organizations keep
their own setting.

## If you lose your device

If you no longer have the phone or app that generates your codes, contact
support at [hello@kugelaudio.com](mailto:hello@kugelaudio.com) from the email
address of your account. After confirming it is you, support can reset 2FA on
your account. Sign in again and set up a new authenticator app right away,
especially if your organization requires 2FA.

A lost passkey does not lock you out: sign in with your password or single
sign-on instead, then remove the old passkey in **Account Settings**.
