HypercubsDRC Docs
how-to developer public

Secure your account

Protect access to your workspaces by verifying your email, using a strong password, and enabling two-factor authentication. These steps matter most for accounts that record production traffic or hold evidence.

Verify your email

Email verification is required for account recovery and important security notices. A new account must verify its email before hosted workflows run.

  1. After you sign up by email, open the verification message and follow the link inside it.
  2. If you cannot find the message, check spam, then request another from the sign-in or profile screen.
  3. Open your profile and confirm the email shows as verified.

Result: your email is verified and account recovery is available if you ever lose access.

Reset your password

If you forgot your password, request a reset from the sign-in screen.

  1. Choose "Forgot password" and enter the email on the account.
  2. Open the reset message and follow the link. The link expires after 30 minutes and works once.
  3. Set a new password and sign in.

Result: the old password no longer works and your new one is active.

Enable two-factor authentication

Use an authenticator app so a stolen password alone cannot open your account.

  1. Open profile settings and go to Security and 2FA.
  2. Choose "Enable 2FA". A QR code appears.
  3. Scan the QR code with your authenticator app, then continue to the code step.
  4. Enter the six-digit code from the app to confirm the enrollment.
  5. Save the recovery codes the screen shows. Store them in a password manager. They are displayed once and never shown again.

Result: sign-in now requires your password and a code from your authenticator, and your recovery codes are stored safely.

Use and manage recovery codes

A recovery code is a single-use backup for when your authenticator is unavailable.

  • Open Security and 2FA and enter a recovery code under Recovery when you lose access to your authenticator.
  • Regenerate recovery codes from the same screen if you think the current set leaked. Existing codes stop working immediately.
  • Disable 2FA only from a verified session, and only when you have a replacement plan in place.

Result: you can recover the account without your authenticator, and codes you no longer trust are retired.

Next: Work with workspaces.