# Account security

> Changing or resetting a password, configuring TOTP two-factor authentication, and managing recovery codes.

Source: https://www.widewired.com/page/docs/account-security

## Changing your password

Under **Account Settings**, enter the current password and a new password between 8 and 128 characters.

## Resetting your password

Open the recovery entry on the sign-in page:

1. Enter the account email address to request a 6-digit reset code.
2. Submit the reset code and a new password.

The reset code is valid for 30 minutes. The page shows the same result after every request; if no email arrives, first check that the address belongs to the account.

A successful reset invalidates every browser session, which must sign in again. Registered devices use separate device identities and are unaffected.

## Two-factor authentication

**Account Settings** supports TOTP two-factor authentication:

1. Start enrolment and scan the QR code with an authenticator app.
2. Enter the current 6-digit code.
3. Store the 10 recovery codes shown once on completion.

Each recovery code works once. Store them securely and separately from the authenticator device.

### Disabling two-factor authentication

Disabling two-factor requires a password or two-factor check within the last 15 minutes. The console requests fresh authentication when that window has expired.

### Replacing recovery codes

Re-enrolling two-factor authentication creates a fresh set. If neither the authenticator nor a recovery code is available, contact support through live chat.

## After changing account security

The client does not store the account password. After changing account security settings:

- Password and two-factor changes do not interrupt devices already in a network.
- Blocking or deleting a device does not affect account sign-in.

If a device can no longer access the network and reports an authentication error, confirm that the device and network still exist, then run the install command again.

## Quick troubleshooting

| Symptom | Check and action |
| --- | --- |
| No password reset email arrives | Verify the email address; a successful request does not prove the account exists |
| TOTP codes keep failing | Check that the authenticator device synchronises its clock automatically, then use the current code |
| A recovery code fails | Confirm it is complete and has not been used; every code works once |
| Two-factor cannot be disabled | Re-authenticate so the password or two-factor check is within the 15-minute window |
| A device reports an authentication error | Confirm account, network and device state; reinstall if needed, and check the code in [troubleshooting](https://www.widewired.com/page/docs/troubleshooting) |
