Security and access
Open Settings → Security & access to manage the ways you sign in and the devices that can use your account.
Verify your email
If your email address isn’t confirmed yet, Twelfth shows a banner across the app — “Verify your email to secure your account” — with the address the link was sent to. Choose Resend email if you need another link. Your verified status is also shown as a Verified badge next to your address in Profile.
If you joined from a workspace invitation, your email is confirmed automatically when you accept — you won’t see the banner. It only appears for self sign-ups whose address hasn’t been confirmed yet.
Sign-in methods
Use your Twelfth email and password, or Google sign-in where your organisation enables it. Use the same verified email address to link Google to an existing account.
Two-factor authentication
2FA uses a code from an authenticator app, such as 1Password, Google Authenticator, or Authy.
- Start setup. Select Set up 2FA and confirm your password if asked.
- Scan the QR code. Scan the Twelfth QR code with your authenticator app.
- Save recovery codes. Save the one-time recovery codes somewhere secure.
- Verify the code. Enter the current authenticator code.
Password sign-ins then require a current code. Trusted devices expire after 30 days.
Do not store recovery codes only in the same password manager or device that you use for your authenticator app. Each recovery code can be used once.
You can disable 2FA here unless your workspace requires it.
Passkeys
Passkeys let you sign in with your device biometrics, device PIN, or a security key. Select Add passkey and complete the device prompt. Keep another sign-in method before removing one.
Signed-in sessions
Review Signed-in sessions and sign out any device you do not recognise. Change your password if you think your account was exposed.