> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pushctl.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Account security

> Change your password, configure two-factor authentication, and manage passkeys.

Open **Settings** → **Security**. Pushctl asks you to confirm your password before showing sensitive security controls.

## Change your password

Enter your current password, enter and confirm a new password, then select **Save**.

## Two-factor authentication

<Steps>
  <Step title="Enable 2FA">Select **Enable 2FA**.</Step>
  <Step title="Scan the QR code">Add the account to a TOTP-compatible authenticator app.</Step>
  <Step title="Confirm the code">Enter the six-digit code to finish setup.</Step>
  <Step title="Save recovery codes">Store the recovery codes somewhere separate from your password and authenticator device.</Step>
</Steps>

When enabled, each password sign-in requires an authenticator code or one unused recovery code. You can view new recovery codes or disable 2FA from the same page.

## Passkeys

Register a passkey to sign in without typing your password. Give each passkey a recognizable name so you can remove a lost or replaced authenticator later.

<Tip>
  Register more than one passkey when possible, for example one on your laptop and one on your phone.
</Tip>
