Protect your account
Open Profile → Security to manage sign-in protection, active sessions, and product analytics consent.
Passkeys are the preferred second factor. ToDoddle also supports time-based authenticator codes as a fallback. When you add the first factor, save the recovery codes in a trusted password manager or another secure location. Each recovery code works once.
After multi-factor authentication is enabled, a correct password alone cannot create a session. Use a passkey, an authenticator code, or one unused recovery code. Adding or removing a factor and generating new recovery codes requires your current password. You cannot remove the final usable primary factor.
The Active sessions list shows the device or browser label, creation time, and recent use for each unexpired session. Revoke a session you do not recognize, or revoke every other session while keeping the current one. Revoking the current session signs it out.
ToDoddle also asks for browser-specific consent before it sends limited product analytics. The approved events record only a signed-in session start and a broad page category. They do not send URLs, search values, ticket content, messages, file names, names, email addresses, or workspace and project IDs. Automatic capture and session replay are disabled. You can change this browser's choice under Product analytics on the same Security page.
If you lose every sign-in factor and recovery code, contact your workspace administrator or support. Support does not remove factors based only on access to an email account.
Updated 2026-08-28. Owned by security.

