Sign-in, passkeys and recovery
Use the sign-in options offered by the hosted app. For password access, use the password-reset flow when you cannot sign in; do not send passwords to support or put them in an automation configuration.
Passkeys and second factors
Section titled “Passkeys and second factors”In user security settings, register a passkey with a browser/device or security key that supports WebAuthn. Name it so you can recognize the device. Registration and sign-in use the browser’s secure credential prompts.
Passkeys can be used in sign-in and second-factor flows. A registered passkey or enabled authenticator-app factor makes additional verification required where applicable. Keep recovery backup codes securely offline.
Review registered passkeys and remove lost or retired credentials. Removing the last passkey does not disable an independently enabled authenticator. Disabling the authenticator does not remove remaining passkeys. Backup-code behavior follows the remaining second-factor methods.
Before retiring your only credential, verify another usable sign-in/recovery path. Do not treat possession of an automation bearer token as a way to recover your interactive account.
Operational access
Section titled “Operational access”Store heartbeat URLs, website verification values and manual automation tokens privately. Public status links are sharing credentials, not account passwords. Rotate/revoke automation connections when their environment or owner changes.
Account roles and authentication are separate: strong sign-in does not grant more permissions, and a role change does not replace credential hygiene.