Account Security
Open Dashboard → Settings → Security to review where your account is signed in, turn on two-factor authentication, manage recognized devices, and read your login history. Every plan includes all of it.
Active sessions
The top section lists your current session and every other session on your account, with its device and last activity.
- Revoke ends one other session.
- Revoke All Others ends every session except the one you are using.
- Log Out Everywhere ends all sessions including this one, so you will sign in again.
Revoke anything you do not recognize, then change your password.
Two-factor authentication
Two-factor authentication (2FA) uses a time-based code from an authenticator app. It is optional and off until you enable it.
- Set an account password first if you only ever signed in with Google — 2FA is confirmed with your password. Settings → Account adds one.
- Press enable, enter your password, and scan the QR code with your authenticator app.
- Save the backup codes somewhere safe and confirm you have stored them. They are your way back in if you lose the app.
- Enter the 6-digit code from the app to finish enrolling.
Disabling 2FA also requires your password. Enabling and disabling both send you a confirmation email.
Once 2FA is on you verify with your authenticator app at sign-in, and the email sign-in code below no longer applies to you.
Known devices and the sign-in code
Devices you have signed in from are listed with a label, when they were added, and when they were last seen. Remove a device when it is no longer yours; the next password sign-in from it has to be verified again.
When you sign in with a password from a device that is not on that list, we email you a 6-digit code to enter before the session starts. Two exceptions keep this from becoming noise:
- Your first ever sign-in is not challenged; there is no history to protect yet.
- Google and magic-link sign-ins are not challenged, because that sign-in already proved control of the email address. The new device is recorded as recognized instead.
Login history and alert emails
Login history shows the recent sign-ins on your account: when, the method used, the device, and the approximate location.
astrostock also emails you when something security-relevant happens:
| Sent when | |
|---|---|
| New sign-in | Your account is used from a device we have not seen before |
| Password changed | Your account password is changed |
| Password added | A password is added to an account that previously signed in with Google only |
| Password reset requested | A reset is requested for an account that signs in with Google |
| Two-factor enabled | 2FA enrollment completes |
| Two-factor disabled | 2FA is turned off |
These are notifications, not requests. astrostock never emails or messages you asking for your password, a 2FA code, or a backup code.
If something looks wrong
- Open Settings → Security and revoke the sessions you do not recognize.
- Remove the unknown device so it must verify again.
- Change your password from Settings → Account.
- Enable two-factor authentication if it is not already on.
- Contact [email protected] if you cannot get back into the account.

