Account & Security
Account pages live under Settings → Account (Profile, Password, Security) and are reachable from the avatar menu. This topic covers everything that protects your account, and everything that gets you back in when something goes wrong.
Profile & password
On Settings → Profile you can change your name and email; changing the email re-triggers verification. Settings → Password changes your password and requires the current one. If you signed up through Google or Telegram and never set a password, you can create one there to make email sign-in possible as a fallback.
Two-factor authentication
On Settings → Security, enable 2FA in under a minute: scan the QR code with any TOTP app (Google Authenticator, 1Password, Aegis…), confirm one code, and save the eight recovery codes: each signs you in once if you lose the authenticator, and they are shown only at setup. From then on, sign-in asks for a code after the password. Disabling 2FA or regenerating codes always requires your password.
Passkeys
The Security page also manages passkeys: sign-in with your device's own unlock (Face ID, Touch ID, Windows Hello, or a hardware security key) instead of typing a password. Add a passkey on each device you use; you can name and remove them individually. Passkeys are phishing-resistant by design: they only work on the real site, so a fake login page gets nothing. They coexist with your password and 2FA; losing a passkey device never locks you out as long as another sign-in method works.
Browser sessions
The same page lists every device where your account is signed in: browser, platform, IP and last activity, with the current device marked. One button (password-confirmed) signs out everything else. Use it whenever you have logged in from a device you no longer control: a shared computer, an old phone, anywhere.
Connected accounts
On Settings → Profile you can link Google and Telegram. A linked account gives one-click sign-in and acts as a recovery path. Linking Google also verifies your email automatically. Unlinking takes one click and never deletes your account data.
If you are locked out
- Forgot the password: use the reset link on the sign-in page; it arrives by email.
- Lost the authenticator: sign in with one of your recovery codes, then disable and re-enable 2FA with the new device.
- Lost both: sign in through a linked Google/Telegram account or a passkey if you have one, then fix 2FA from Settings → Security.
- Lost everything: contact support from the email address on the account.
Deleting your account
Account deletion lives at the bottom of the Profile page. It is password-confirmed and permanent: your data, settings, pins and history are removed. If you have an active plan, remember there is no auto-renewal to cancel; deletion simply ends everything immediately.
Good hygiene, thirty seconds
- Enable 2FA, store the recovery codes somewhere that is not this device.
- Add a passkey on your daily devices; it is faster than a password and safer.
- Skim the sessions list occasionally; sign out anything you do not recognize.
- Use a unique password; the exchange account connected to your bot deserves the same care.
Common questions
What is a passkey?
A sign-in that uses your device's own unlock: Face ID, Touch ID, Windows Hello or a hardware key. Passkeys only work on the real site, so a fake login page gets nothing, and they coexist with your password and 2FA.
What if I lose my authenticator?
Sign in with one of your recovery codes, then disable and re-enable 2FA with the new device. No codes either? Use a linked Google or Telegram account or a passkey. Lost everything: contact support from the email address on the account.
How do I secure my Osiris account?
Enable 2FA on Settings, then Security (any TOTP app works), store the eight recovery codes somewhere that is not this device, and add a passkey on the devices you use daily. The same page lists every active session and one button signs out everything else.