Skip to content

Account security

Every account, including those created with GitHub, verifies its email address with a 6-digit code before it can create resources or deploy. See Create an account.

Protect your account with codes from an authenticator app (such as 1Password, Google Authenticator or Authy).

  1. Go to Settings → Security → Two-Factor Authentication and click Setup 2FA.
  2. Scan the QR code with your authenticator app (or enter the key manually).
  3. Enter the 6-digit code from the app and click Verify & Enable.
  4. Save your 10 backup codes somewhere safe. Each works once and lets you in if you lose your device.

From then on, after your password you’ll be asked for an Authentication code: a 6-digit code from your app, or an 8-character backup code. This also applies when you sign in with GitHub and when you use hivepod login --no-browser.

Running setup again replaces your backup codes.

Click Disable and enter your password.

  • Change your password in Settings → Security.
  • Forgot it? Use Forgot password on the sign-in page. The link works once, for one hour, and resetting signs you out everywhere.
  • Passwords must be at least 8 characters and not too common or too similar to your email.
  • After 5 failed sign-ins in 15 minutes, sign-in for that account pauses for 15 minutes.
  • Sign-up, sign-in and password resets include a quick, automatic security check against bots.
  • DockHive emails you when your account is signed in to, and when an API key is created. If it wasn’t you, change your password and revoke unknown keys.

Use API keys with the narrowest access you need (Read only where possible) and an expiry. Keys can never change your account, security or billing settings.

Email partners@dockhive.io.