Your sign-ins and two-factor
Read the list of devices signed in to your account, sign one or all of them out, and turn on two-factor authentication.
Every time you sign in, your account opens a session — a signed-in place that stays open until it is signed out. Sessions are per browser and per device, not per tab: opening five tabs of Alchex uses the one session you already have. Settings → Security lists every session your account currently has open, and lets you close any of them.
Reading the list
Each row names one signed-in device:
Chrome · Windows — Türkiye · 176.88.141.197 · last active 3 minutes ago
- The device is the browser and operating system that signed in.
- The country is worked out from the network address the sign-in came from. It is deliberately coarse — the country, never the town or the street — because it is there to help you recognise your own sign-ins, not to place anyone.
- Last active is when that session was last used, which is the part worth reading. A session opened two days ago but untouched since is a very different thing from one that was active a minute ago.
The session you are reading this on is marked This device. It has no Revoke button, because signing yourself out from here would be a strange way to do it — use the normal sign-out for that.
"Unknown device"
A row reads Unknown device when the browser is one we could not confidently name, or when the session was opened before your workspace started recording devices. It is not a warning in itself. We would rather say we do not know than put a confident, wrong name on a device you are deciding whether to trust.
If you want a clean list, use Sign out everywhere else once and sign back in on the devices you use — every row after that will be named.
Signing a session out
Revoke on any row closes that one session. Whoever was using it is signed out and has to sign in again; nothing else about the account changes.
Sign out everywhere else closes every session except the one you are using. This is the right move if you have lost a laptop or phone, if you signed in on a shared computer, or if you see a sign-in you do not recognise. It signs out every other device, however many there are.
It takes effect immediately. The next thing that device asks Alchex for is refused — it does not get a grace period, and it cannot renew itself. A page already open there may keep showing what it had already loaded, because a rendered page makes no request until you click something; the moment it does, that person is at the login screen.
Sessions do not close themselves quickly. Closing a browser leaves its session open, so a list of ten sign-ins usually means ten times you have signed in, not ten devices sitting logged in right now. That is normal, and the two controls above are how you tidy it.
Accounts that sign in very often — an automated one, say — can accumulate hundreds. The list shows your 200 most recent sign-ins and tells you when there are more; Sign out everywhere else still closes every one of them, not just the ones on screen.
Two-factor authentication
Two-factor means a stolen password is not enough on its own: signing in also needs a six-digit code from an app on your phone.
To turn it on, choose Set up under Two-factor authentication. Alchex shows a QR code — scan it with an authenticator app (Google Authenticator, 1Password, Authy, or any other), then type the six-digit code the app shows to confirm. The code proves the app really holds the secret; setup is not finished until it matches.
The QR code and its setup key are shown once. If you close the panel before scanning, the half-finished setup is discarded and you start again — nothing is left behind on your account.
There is no way to turn it off. An authenticator is required on every account, so once one is set up it stays — there is no button to remove it, for you or for an admin. If you lose the device your authenticator lives on, ask your workspace owner: recovery is a deliberate, person-checked step rather than a self-service switch, because anything self-service here would be a way around the requirement.