Skip to main content

Account Security

BeePass provides several mechanisms to protect your account: two-factor authentication, active session management, device verification, and account deletion. All these settings are accessible from Settings then the Security tab.

Two-Factor Authentication (TOTP)

Enabling TOTP (Time-based One-Time Password) adds an extra layer of security to your login. This feature is optional for breeders.

Enabling TOTP

  1. Go to Settings then the Security tab
  2. Click Enable Two-Factor Authentication
  3. Scan the displayed QR code with your authenticator app (Google Authenticator, Authy, Microsoft Authenticator, or any compatible app)
  4. Write down the 8 backup codes (format XXXX-XXXX) and store them in a safe place
  5. Tick the checkbox confirming you have saved your backup codes
  6. Enter the 6-digit code displayed by your app to confirm activation
Backup Codes

The 8 backup codes are your only recourse if you lose access to your authenticator app. Each code can only be used once. Store them in a secure location (password manager, safe). They will never be displayed again after this step.

Logging In with TOTP

Once TOTP is enabled, the login process takes place in two steps:

  1. Enter your email and password as usual
  2. BeePass prompts you for a 6-digit code -- open your authenticator app and enter the displayed code

If you do not have access to your app, use one of your backup codes instead of the 6-digit code.

Disabling TOTP

You can disable TOTP from the Security tab. Verification of your current TOTP code is required to confirm deactivation.

New Backup Codes

If you have used up all your backup codes, disable and then re-enable TOTP. A new set of 8 codes will be provided.

Active Sessions

The Security tab displays the list of your active sessions with the following information:

InformationDescription
BrowserChrome, Firefox, Safari, etc.
Operating SystemWindows, macOS, Linux, iOS, Android
IP AddressConnection IP
LocationCity and country (estimate)
Last ActivityDate and time of the last access

You can revoke an individual session by clicking Disconnect next to it. The disconnection takes effect immediately on the affected device.

Suspicious Sessions

If you do not recognise a device or location, revoke the session immediately and change your password.

Changing Your Password

To change your password:

  1. Open the Security tab
  2. Enter your current password
  3. Enter the new password (minimum 8 characters, including at least one uppercase letter, one lowercase letter, one digit, and one special character)
  4. A strength indicator helps you choose a strong password
  5. Confirm

When you change your password, all your existing sessions are automatically revoked. You will need to log in again on each device.

Device Verification

When you log in from a new device (new browser, new computer, or new phone), BeePass performs a silent verification based on the device fingerprint. If the device is not recognised, a discreet notification informs you. No action is required on your part: this measure is designed to detect unusual login activity.

Deleting Your Account

Account deletion is permanent and irreversible. To delete your account:

  1. Open the Security tab
  2. Scroll down to the Danger Zone section
  3. Click Delete My Account
  4. Confirm in the dialog box
Irreversible Deletion

Deletion results in the loss of all your data: queens, evaluations, pedigrees, conversations, and contacts. Queens you have shared on the BeePass Index will remain visible but will no longer be associated with your profile.

See Also