> ## Documentation Index
> Fetch the complete documentation index at: https://docs.keloa.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Password & 2FA

> Change your password and enable two-factor authentication.

Secure your Keloa account with a strong password and two-factor authentication. Admins can require 2FA for the whole workspace — see [Security](/settings/security).

## Change password

<Steps>
  <Step title="Open your profile">
    Top-right avatar → **Profile** → **Password**.
  </Step>

  <Step title="Confirm current password">
    Type your current password, then the new one twice.

    New passwords must be at least 10 characters; long passphrases beat short cryptic ones.
  </Step>

  <Step title="Save">
    You stay signed in on this device; other sessions are revoked.
  </Step>
</Steps>

## Forgot your password

From the login screen → **Forgot password** → enter your email. You'll receive a reset link. Clicking it lets you set a new password without knowing the old one.

The link is good for 60 minutes and only usable once.

## Enable 2FA

<Steps>
  <Step title="Open 2FA">
    Profile → **Two-factor authentication** → **Enable**.
  </Step>

  <Step title="Scan the QR code">
    Open your authenticator app (Authy, 1Password, Google Authenticator, Bitwarden) and scan the QR.
  </Step>

  <Step title="Confirm with a code">
    Enter the 6-digit code your app shows. If it matches, 2FA is active.
  </Step>

  <Step title="Save recovery codes">
    Keloa generates 8 one-use recovery codes. Save them somewhere safe (password manager, printed in a drawer). If you lose your phone, these are how you get back in.
  </Step>
</Steps>

## Disable 2FA

Profile → **Two-factor authentication** → **Disable**. Re-authenticate with password and a current code.

Admins may have required 2FA for the whole workspace — in that case, you'll be prompted to re-enable it at next login. You cannot opt out while the workspace requires it.

## Lost your 2FA device

1. Try a recovery code from the list you saved.
2. If you don't have one, a workspace admin can reset your 2FA in **Settings → Members** → your profile → **Reset 2FA**.
3. If you're the only admin, email [support@keloa.ai](mailto:support@keloa.ai) with proof of account ownership.

## SSO

If your workspace has SSO enabled (Scale plan), your identity provider handles password + 2FA — this page is bypassed for you. See [Security](/settings/security).
