Skip to main content
PARIXDocs
Security

Account security

Use passkeys, TOTP two-factor authentication, session controls, and security logs.

Account protections apply to your Parix user across every organization. Open Settings → Account to manage passkeys and two-factor authentication, then use Sessions and Security log for ongoing review.

Add and manage passkeys

Passkeys let you sign in with device biometrics, a device PIN, or a hardware security key.

  1. Open Settings → Account.
  2. In Passkeys, optionally enter a label such as Work MacBook.
  3. Select Add passkey and complete the browser or operating-system prompt.

The registered list identifies synced or single-device passkeys, whether a credential is backed up, and when it was added. Remove any passkey for a device or security key you no longer control.

Passkeys are an account sign-in method. The current organization model does not let an owner require passkeys for all members.

Enable TOTP two-factor authentication

TOTP 2FA is currently available only for accounts that have password sign-in. Google-only accounts cannot enable it in this release.

  1. Open Settings → Account → Two-factor authentication.
  2. Enter your current password.
  3. Scan the QR code with a TOTP authenticator app.
  4. Save the displayed backup codes somewhere separate from the authenticator device.
  5. Enter the current six-digit code to finish setup.

Each backup code is single-use. Regenerating backup codes and disabling 2FA both require the current password. The dashboard does not currently offer SMS, email-code, or organization-enforced 2FA.

Review and revoke sessions

Open Settings → Sessions. The page shows each signed-in session's:

  • browser and operating system derived from its user agent
  • IP address, when available
  • last-active, created, and expiration times
  • whether it is the current session

The runtime session lifetime is seven days, with activity-based refresh. You can revoke any other session immediately. The current session cannot be revoked from this page; use Sign out to end it.

If you see an unfamiliar session, revoke it first, then review the security log and reset any affected credentials.

Review the security log

Open Settings → Security log. This account-scoped log retains 15 days of authentication activity and displays 25 events per page.

You can filter these event types:

  • signed in and signed out
  • session created
  • one session revoked
  • all sessions revoked
  • user impersonated
  • impersonation stopped

Each row shows actor, action, event code, IP address, location, and time when available. Unknown IP or Unknown location means the request metadata was not available; it does not by itself indicate abuse.

The account security log is not the organization audit log. Membership, invitation, organization settings, backup, and database control-plane actions appear under the active organization's Audit log.

Account-safety response checklist

For a suspected account compromise:

  1. Revoke every unfamiliar session.
  2. Sign out the current session and sign in again after changing the password, if applicable.
  3. Remove unknown passkeys.
  4. Regenerate TOTP backup codes if they may have been copied.
  5. For every organization you manage, rotate or delete affected API keys.
  6. Review both the account security log and each organization's audit log.
  7. Ask another owner or administrator to review membership and pending invitations.

Parix does not currently ship an organization-wide “revoke every member session” control. Session actions on this page apply to the signed-in user.