Skip to content

Password, passkeys, and two-step verification

This one page holds everything that protects your account. You reach it from the gear icon in the dashboard’s top bar, and it stays reachable even when the rest of the dashboard will not load, so you can always get back in.

The Password row shows No password set if you sign in with an email code or a provider only. Choose Set password (or Change, if one exists) and fill in:

  • New password — a live checklist shows the requirements as you type; the first is At least 12 characters.
  • Confirm new password — if the two differ you see “New passwords do not match.”

Choose Update password or Set password to save. You need a password before you can turn on two-step verification.

A passkey lets you sign in with your device’s own unlock — fingerprint, face, or PIN — instead of a password.

  • Add passkey registers one with your browser and names it “Homeward passkey”, numbered from the second onwards.
  • Each passkey card shows an editable name, Added date, and whether it is a Synced passkey (backed by your cloud account, so it follows you to other devices) or a Device passkey (stays on this device only).
  • Rename saves a non-empty name. Remove asks “Remove ?” in a browser dialog, then deletes the passkey for good.

If Homeward is open on a domain different from the one passkeys are bound to, you see “Passkeys can’t be added from this domain”. Existing passkeys stay manageable, and you can add new ones from the right domain.

Authenticator app (TOTP) asks for a 6-digit code from an authenticator app on every sign-in, on top of your password or email code. You need a password first — the Set up button is disabled until one exists.

Turning it on takes three steps:

  1. Enter your Current password and continue.
  2. Scan the QR code with your authenticator app, or enter the key manually. Then save your backup codes: Copy codes or Download gives you a file. Save them somewhere safe — each one works once if you lose your authenticator, and they will not be shown in full again.
  3. Enter the current 6-digit code and choose Verify & turn on.

When it is on, you can Turn off two-step verification (your current password required) or Regenerate a fresh set of backup codes if you have used or lost yours.

The bottom band lists Google, Facebook, and Apple. Each tile shows whether it is linked, and when. Link starts the provider’s sign-in; Unlink removes it.

Unlinking is immediate and has no confirmation dialog — a misclick really does unlink. If a link attempt fails, the message tells you which of three things happened: it was cancelled, that provider account is already linked to another Homeward account, or the attempt simply failed and is worth retrying.

This table lists every device currently signed in as you, with the device type, IP address, when it was last active, and when it expires. Sign out on a row revokes that session immediately — useful if a phone or shared computer is still holding a session you no longer control.

The top of the page also holds your account preferences:

  • Email — shown read-only. If it is not yet verified, Verify Email sends a verification email; confirmed addresses hide the button.
  • Time zone — the pencil control opens a dropdown of time zones; saving happens as soon as you choose. An unset time zone falls back to UTC.
  • Date format — YYYY-MM-DD, MM/DD/YYYY, or DD/MM/YYYY. The default is YYYY-MM-DD.

There is no delete-account or change-email control on this page; those live in the finish-account flow.

Related: Signing in, Preferences and your Letters edition.