CoreSkill
Language
Sign in
All sections

Account & security

Your profile, language, theme, password, two-factor authentication and backup codes.

Open Settings under Account in the sidebar. The page has three tabs: Profile, Security and Appearance.

Profile

You can change your Display name (up to 100 characters). That is the name your team sees next to the servers you publish, and in the logs. Your email is fixed and can't be changed: it is your sign-in identity, and the address invitations are matched against.

Appearance and language

  • Theme gives you Light (the default) or Dark. It applies instantly, with no Save to press, and is remembered per device.
  • Language takes English or Tiếng Việt, then press Save. This one belongs to your account, so it follows you to every device you sign in from.

After you switch language the page simply redraws in the new one, with no green confirmation. That is correct behaviour, not a broken button.

Changing your password

Security tab → Change password card. Enter your Current password and your New password (at least 8 characters).

Changing your password signs you out everywhere

That is deliberate. If you are changing your password because you suspect someone got into your account, leaving them sitting in an old session would defeat the whole point. Afterwards you land back on the sign-in screen with the message Password changed. You've been signed out on every device - sign in again with your new password. Do that and you're back in.

If you've forgotten it, use Forgot your password? on the sign-in screen: enter your email, take the 6-digit code, set a new password. Resetting a password also ends every open session.

The forgotten-password page deliberately never says whether an email exists: an unknown address gets exactly the same answer. That keeps the page from becoming a way to harvest your user list.

Accounts that only ever signed in with Google or Facebook (and never set a password) can't change a password here.

Two-factor authentication (2FA)

Strongly recommended if you are an Owner, an Admin or a Manager. Your account can issue keys for the whole company, so a leaked password alone should not be enough to get in.

  1. Security tab → Two-factor authentication card → click Set it up.

  2. Scan the QR code with an authenticator app (Google Authenticator, 1Password, Authy…).

    If you can't scan, use the Can't scan? Enter this key by hand: field.

  3. Type the 6-digit code into Enter the 6-digit code to finish and press Turn it on.

  4. Save the 10 backup codes that appear, then press I've saved them.

    There's a button to copy the whole set. This is the only time they are shown.

The QR code and the backup codes live for 2 minutes

Both the QR step and the backup-code card expire after 120 seconds. Past that you have to press Set it up again from the start, or generate a fresh set of codes. Have your phone and somewhere to store them ready before you begin.

From your next sign-in on, entering the right password brings up the Two-step verification step. The form submits itself as soon as the sixth digit lands.

Backup codes

  • There are 10 codes, shaped xxxx-xxxx, and each one works exactly once.
  • Use one instead of the 6-digit code when your phone is gone: at the verification step, click Use a backup code instead.
  • Keep them somewhere that isn't your phone, such as a password manager, or printed and locked in a drawer. Losing both the phone and the codes means losing the account.
  • At 2 codes or fewer the system warns you: You're running low on backup codes. Generate a new set.

To generate a fresh set: enter your Current code (a 6-digit code or one backup code) and press Generate new codes. All 10 old codes die on the spot.

Turning 2FA off

It asks for both factors: your password and a current code. Once it is off, the secret and every backup code are wiped, so turning it back on means scanning a new QR code.

2FA and signing in with Google/Facebook

With 2FA on you can no longer sign in with Google or Facebook, because neither button can carry the code step. You'll see the line This account uses two-step verification, which Google and Facebook can't carry. Sign in with your email and password. Dropping that branch would open a way around 2FA, so it is deliberate.

If you use Google/Facebook and have never set a password, set one through Forgot your password? first, and only then turn on 2FA.

Habits worth keeping

  • Use a long password you use nowhere else. A passphrase you can remember is good enough.
  • Turn on two-factor: a stolen password alone won't get anyone in.
  • Keep your backup codes somewhere that isn't your phone.
  • Revoke skill keys the day someone leaves the team.
  • One key per machine, named after the machine, so losing one doesn't touch the others.

Leaving a business

Go to Business settingsDanger zoneLeave business. You lose access to the business's servers and your keys stop working. An owner can't leave until they Transfer ownership to someone else.