Account Security

🔐

Open Dashboard → Settings → Security to review where your account is signed in, turn on two-factor authentication, manage recognized devices, and read your login history. Every plan includes all of it.

Active sessions

The top section lists your current session and every other session on your account, with its device and last activity.

  • Revoke ends one other session.
  • Revoke All Others ends every session except the one you are using.
  • Log Out Everywhere ends all sessions including this one, so you will sign in again.

Revoke anything you do not recognize, then change your password.

Two-factor authentication

Two-factor authentication (2FA) uses a time-based code from an authenticator app. It is optional and off until you enable it.

  1. Set an account password first if you only ever signed in with Google — 2FA is confirmed with your password. Settings → Account adds one.
  2. Press enable, enter your password, and scan the QR code with your authenticator app.
  3. Save the backup codes somewhere safe and confirm you have stored them. They are your way back in if you lose the app.
  4. Enter the 6-digit code from the app to finish enrolling.

Disabling 2FA also requires your password. Enabling and disabling both send you a confirmation email.

Once 2FA is on you verify with your authenticator app at sign-in, and the email sign-in code below no longer applies to you.

Known devices and the sign-in code

Devices you have signed in from are listed with a label, when they were added, and when they were last seen. Remove a device when it is no longer yours; the next password sign-in from it has to be verified again.

When you sign in with a password from a device that is not on that list, we email you a 6-digit code to enter before the session starts. Two exceptions keep this from becoming noise:

  • Your first ever sign-in is not challenged; there is no history to protect yet.
  • Google and magic-link sign-ins are not challenged, because that sign-in already proved control of the email address. The new device is recorded as recognized instead.

Login history and alert emails

Login history shows the recent sign-ins on your account: when, the method used, the device, and the approximate location.

astrostock also emails you when something security-relevant happens:

EmailSent when
New sign-inYour account is used from a device we have not seen before
Password changedYour account password is changed
Password addedA password is added to an account that previously signed in with Google only
Password reset requestedA reset is requested for an account that signs in with Google
Two-factor enabled2FA enrollment completes
Two-factor disabled2FA is turned off

These are notifications, not requests. astrostock never emails or messages you asking for your password, a 2FA code, or a backup code.

If something looks wrong

  1. Open Settings → Security and revoke the sessions you do not recognize.
  2. Remove the unknown device so it must verify again.
  3. Change your password from Settings → Account.
  4. Enable two-factor authentication if it is not already on.
  5. Contact [email protected] if you cannot get back into the account.

Related guides

  • Stars for balances and AI feature costs
  • Referrals for invite links and rewards
  • Support for contact details and plan notes