> ## Documentation Index
> Fetch the complete documentation index at: https://docs.conversion.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Password and Security

> Protect your Conversion account with 2-step verification and passkeys, and review the browsers and devices you're signed in on.

The **Password and security** page is where you add extra protection to your own account and manage your active sessions. These settings apply to your account only; workspace-wide requirements such as mandatory MFA or SSO are configured by administrators under [Identity and access](/product-docs/workspace-settings/identity-and-access/overview).

## 2-step verification

Prevent unauthorized access to your account with an additional layer of security at sign-in.

### Authenticator

Get verification codes from an authenticator app. It works even if your phone is offline.

<Steps>
  <Step title="Click Enable">
    The **Enable 2-step verification** dialog opens with a QR code.
  </Step>

  <Step title="Scan the QR code">
    Scan it with your authenticator app to add Conversion.
  </Step>

  <Step title="Enter the 6-digit code">
    Type the code your app shows and click **Verify**. From then on you'll be asked for a code when you sign in.
  </Step>
</Steps>

To turn it off, click **Disable** and confirm. You'll no longer be asked for a code when signing in.

<Note>
  If your workspace requires MFA, you must keep 2-step verification enabled to access it. Members signing in with SSO are exempt from that requirement.
</Note>

### Passkeys

Securely sign in to your account using just your fingerprint, face, screen lock, or security key.

Click **Add** and follow your browser or device prompt to create the passkey. Each passkey you've added is listed with how many times it has been used. Click the trash icon next to a passkey to remove it.

## Sessions

This section lists the browsers and devices you are currently signed in on. Each entry shows the device type, browser, and when it was last used. Your current session is marked with a **Current device** badge.

* Click **Sign out** next to the current device to end this session.
* Click the trash icon next to any other session to revoke it. That browser or device will have to sign in again.

<Tip>
  If you see a session you don't recognize, revoke it and enable 2-step verification or add a passkey.
</Tip>
