Skip to content
Draft. Customer sending is not open yet; details on this page may change before launch.

Sign-in and two-factor

Your account is protected by a password and an authenticator app (TOTP). Sensitive actions, such as creating or revoking credentials and changing domains, ask for your second factor again, even when you’re already signed in.

API keys and SMTP passwords appear once, when you create them. weneed.email stores only a value that can check them, never the secret itself, so it can’t show them again. If you lose one, revoke it and create a new one.

  1. Create the replacement.
  2. Switch your application to it.
  3. Revoke the old one once you’ve confirmed the switch.

Revoking holds any of the old credential’s unsent messages for your review.