Docs / Account and secure sign-in
Account and secure sign-in
Manage password, authenticator, passkeys, recovery codes, and sessions in Security. Enable only a second factor you can finish yourself.
- After sign-in open /account/security and check that another sign-in path and recovery codes exist.
- To add an authenticator or passkey, finish the on-page flow. Never share the QR code, recovery codes, or password.
- Before losing a device, make sure another path home exists. Revoke a single device's session from Security when needed.
- If you forget your Hoop's password, go to /en/reset/: the reset happens on your own machine, and HoopGram holds no key to it.
Evidence
anonymous GET /account=302; Location=/login?returnTo=%2Faccountauthenticated GET /account=200 is a separate server-verified session factGET /account/security=302; Location=/account#securityauthenticated Account UI exposes TOTP, passkeys, recovery codes, sessions