Security Settings
Manage your password, two-factor authentication, and account security options.
Security settings help protect your Plotwise account from unauthorized access. This guide covers password management, two-factor authentication, and other security features.
Accessing Security Settings
- Click your avatar (top right)
- Select "Account settings"
- Click "Security" tab
Password Management
Password Requirements
- Minimum 8 characters
- Maximum 72 characters
- Mix of letters, numbers, special characters (recommended)
Changing Your Password
- Go to Security settings
- Enter current password
- Enter new password
- Confirm new password
- Click "Update Password"
Tip: Use a password manager to generate and store strong, unique passwords.
Password Reset
If you forgot your password:
- Go to sign-in page
- Click "Forgot password"
- Enter your email
- Check email for reset link
- Click link and set new password
Two-Factor Authentication (2FA)
Two-factor authentication adds an extra layer of security by requiring a code from your phone in addition to your password.
Enabling 2FA
- Go to Security settings
- Find "Two-Factor Authentication" section
- Click "Enable 2FA"
- Scan QR code with authenticator app
- Enter the 6-digit code shown in your app
- Save your backup codes securely
Supported Authenticator Apps
- Google Authenticator
- Authy
- 1Password
- Microsoft Authenticator
- Any TOTP-compatible app
Backup Codes
When enabling 2FA, you receive backup codes:
- 10 single-use codes
- Use if you lose access to authenticator
- Store securely (password manager, printed)
- Generate new codes if needed
Signing In with 2FA
- Enter email and password
- When prompted, open authenticator app
- Enter 6-digit code
- Code refreshes every 30 seconds
Disabling 2FA
- Go to Security settings
- Click "Disable 2FA"
- Enter your password to confirm
- 2FA removed
Warning: Disabling 2FA reduces account security. Only disable if necessary.
Connected Accounts
If you signed up with OAuth (Google/Microsoft):
Viewing Connected Accounts
Security settings shows:
- Which OAuth providers are linked
- When they were connected
Disconnecting OAuth
- Find connected account
- Click "Disconnect"
- Confirm action
Note: You must have a password set before disconnecting OAuth to maintain account access.
Session Management
Active Sessions
View where you're signed in:
- Current session
- Other devices/browsers
- Last activity time
Sign Out Other Sessions
- Go to Security settings
- Find "Active Sessions"
- Click "Sign out all other sessions"
- Confirm action
Use this if:
- You suspect unauthorized access
- You used a shared/public computer
- You want to reset all sessions
Security Best Practices
Strong Passwords
- Use 12+ characters
- Mix upper/lower case, numbers, symbols
- Avoid personal information
- Use unique password for Plotwise
Enable 2FA
- Strongly recommended for all accounts
- Protects even if password is compromised
- Small inconvenience for major security gain
Review Sessions Regularly
- Check active sessions monthly
- Sign out unused sessions
- Investigate unknown sessions
Keep Recovery Options Updated
- Email address current
- Phone number accurate
- Backup codes stored safely