Signing in and security

Your password, two-factor authentication, passkeys, and what to do if you are locked out.

2 minute read

Your account is yours and follows you across every studio. These settings are in Settings → Security.

Your password

Changing it means giving the current one first. That is what stops a session left open on a shared machine being used to take the account over.

If you have forgotten it, the sign-in page sends a reset link to your address. The link is single-use and expires.

Two-factor authentication

Once it is on, signing in asks for a code as well as the password. You scan a QR code with an authenticator app, then confirm with a first code.

Kalepio also gives you recovery codes. Write them down somewhere other than the phone generating the codes: they are the only way in if you lose that phone, and the only time you get to see them.

This is the setting to turn on first if your studio takes payments: somebody getting into your account sees your clients, your files and your Stripe setup.

Passkeys

A passkey replaces the password with whatever already unlocks your device: a fingerprint, a face, a device PIN.

It is faster and safer: there is no password to steal, and a passkey only works on the site it was created for, which makes it useless on a fake sign-in page.

You can register several, one per device, and name them so you can tell them apart. Keep the password and the recovery codes anyway: they are your way in on a device that has no passkey.

An e-mail address that matters

It is where your clients' notifications and your reset links arrive. Changing it asks for a fresh confirmation, for the same reason as at sign-up: an unverified address is a notification nobody receives.

Signing out

Signing out ends the session on that device. On a shared computer it is the thing not to forget: closing the tab is not enough.

Updated on August 9, 2026

Read next