account/Settings

Settings

Manage your SikkerKey profile, passwords, two-factor authentication, passkeys, vault encryption, organization membership, sessions, and account lifecycle.

Updated 2 days ago

Account Settings brings together your profile, sign-in methods, passkeys, vault encryption, organization choices, and account lifecycle controls. The options on the page adapt to your sign-in methods, subscription, vault ownership, and the vault you are currently using.

#Open Account Settings

Sign in to the SikkerKey dashboard.

In the sidebar, open Account, then select Settings.

Choose the section you want to update. Sensitive changes ask you to confirm your identity before they are applied.

Verify your account email before changing security settings. Your Settings page shows the email associated with your account for reference.

#Profile

Change your username

Your username is the name shown throughout SikkerKey and in activity records. It is a display name rather than a sign-in credential, so changing it keeps your current sessions active.

In the Account panel, select Edit beside your username.

Enter a unique username using 3–32 letters, numbers, underscores, or hyphens.

Select Save.

#Password

The password panel lets you set a password on an account that does not have one, or replace your current password. Adding a password gives a passkey- or provider-based account another supported way to sign in.

Set or change your password

Open the Set Password or Change Password panel.

When changing an existing password, enter your current password.

Enter and confirm the new password, then save the change.

Passwords must be 12–128 characters long, contain at least one number and one special character, and use a varied mix of characters. SikkerKey also rejects common passwords and passwords containing your username or the part of your email address before the @ sign.

After a password is set or changed, your current session stays active and every other session is signed out.

Remove your password

Passwordless mode is available when your account already has a passkey or a connected sign-in provider. Removing the password makes those methods your sign-in path. If a passkey remains, passwordless passkey sign-in is enabled automatically.

In Passwordless mode, select Remove password.

Confirm the change.

Complete the fresh passkey check when prompted.

Your current session stays active and all other sessions are signed out. You can set a new password again from the same page.

#Two-factor authentication

SikkerKey supports time-based one-time passwords from authenticator apps. When enabled, the account asks for a current six-digit code during sign-in.

Enable two-factor authentication

Select Enable 2FA.

Scan the QR code with your authenticator app, or enter the displayed setup key manually.

Enter a current six-digit code from the app and select Verify & Enable.

Save the recovery codes shown after setup in a secure place.

Recovery codes are shown during setup so you can save them. Each code works once and can be used when you cannot access your authenticator app.

Enabling two-factor authentication keeps your current session and signs out every other session.

Disable two-factor authentication

Select Disable 2FA, confirm the change, and enter your current password. When passkeys are registered, SikkerKey also asks for a fresh passkey confirmation. Disabling two-factor authentication removes its setup key and recovery codes and signs out your other sessions. A passwordless account must set a password before turning 2FA off.

#Passkeys

Passkeys let you confirm sign-in with a device authenticator, password manager, or hardware security key. The Passkeys panel shows each registered passkey’s name, type, supported connection methods, enrollment date, and most recent use.

Add your first passkey

Adding the first passkey requires an existing proof of identity. Use your current password or a code from your authenticator app. An account with only a connected sign-in provider can set a password or enable 2FA first.

Select Add passkey.

Choose Password or 2FA code when both are available, then confirm your identity.

Follow your browser or device prompt to create the passkey.

Save any recovery codes shown after enrollment.

Add, rename, or remove passkeys

Select Add another passkey to register a backup device or hardware key. Select a passkey name to rename it, or select Remove to revoke it. These changes require a fresh confirmation with one of your existing passkeys.

SikkerKey protects your remaining sign-in path when you remove a passkey. A removal is blocked if it would leave the account without a usable sign-in method or would break an enabled passkey policy.

Register at least two passkeys before making passkeys mandatory. A second passkey gives you a backup if your primary device is lost or unavailable.

Choose how passkeys are used

Setting

How it works

Requirement

Allow passwordless sign-in

A passkey can complete sign-in without entering a password first.

At least one registered passkey.

Require passkey at sign-in

Normal sign-in must be completed with a passkey, even when the account also has a password or authenticator app.

At least two registered passkeys.

Changing either policy requires a fresh passkey confirmation. When Require passkey at sign-in is enabled, keep your recovery codes somewhere separate from your passkey devices.

Recover access after losing your passkeys

From the sign-in page, select Lost your passkey? and enter your email with one unused recovery code. Successful recovery removes every registered passkey, turns off both passkey policies, signs out all other sessions, and creates a new session for you. Return to Settings to register new passkeys from devices you control.

#Vault encryption

Vault owners can manage Bring your own key from Settings. This Enterprise feature lets you encrypt the vault’s project keys under a key you control in Google Cloud KMS or OVHcloud KMS.

Connect your key

Select Connect your key and choose your cloud KMS provider.

Complete the provider-specific authorization shown in the setup wizard.

Enter the requested key details and review the connection.

Select Connect and encrypt. SikkerKey verifies access and re-encrypts the vault’s project keys while secrets remain available.

The panel shows the connected provider, key details, connection date, and certificate information when OVHcloud KMS is used. OVHcloud connections can be renewed from Settings, and you can schedule an email reminder before the certificate expires.

Keep the customer-managed key and SikkerKey’s authorized access available. Secret reads pause whenever SikkerKey cannot reach the key. Permanently losing or deleting the key makes the vault impossible to decrypt.

Disconnect your key

Select Disconnect key to move the vault back to SikkerKey-managed encryption. Keep the customer-managed key available until the re-encryption finishes; it is needed to complete the transition.

#Organization settings

The organization section changes according to your relationship with the active vault.

Convert a personal vault to an organization

A vault owner can convert a personal vault when organizations are included in the current plan. The vault keeps its projects, secrets, machines, and history, and gains team invitations, roles, and member-level attribution.

Select Convert to organization.

Enter an organization name of up to 100 characters.

Confirm with the security methods configured on your account.

Select Convert to organization.

Conversion is a one-way change. Set up a password or passkey before converting.

Leave an organization

When you are viewing an organization you joined, Settings provides a Leave organization panel. Leaving removes your access role, project scope, and access to that organization immediately. Your SikkerKey account, personal vault, and memberships in other organizations remain available.

Select Leave organization.

Type the organization name exactly as shown.

Confirm the action.

You return to your personal vault, the organization owner is notified, and a new invitation is required if you want to join again.

#Destroy your vault and account

The Danger Zone is available to the owner of the active vault. Destroying the vault closes the owner’s SikkerKey account, ends active sessions, cancels its subscription, removes organization memberships, and removes access for organization members.

Projects, secrets and their version history, machines, integrations, support data, and other operational vault data are removed immediately. Remaining account, billing, security-history, and audit records are erased after the retention window completes; encrypted backups roll off within approximately 30 days.

Set a password first if the account currently uses passwordless sign-in.

Select Destroy Vault.

Enter your password and, when enabled, a current 2FA code. Accounts with registered passkeys also require fresh passkey confirmation.

Type DESTROY MY VAULT exactly.

Select Permanently Destroy Vault.

Vault destruction cannot be undone. Export or move anything you need before confirming the action.

#Review and revoke active sessions

Open Account, then Sessions to review every active sign-in. Each entry shows the browser or device, IP address, available location, creation time, last-used time, and whether it is your current session.

You can revoke an individual session or select Revoke all others. Your current session is kept; use Logout when you want to end it.

#How security changes affect sessions

Change

Session effect

Change username

Existing sessions stay active.

Set or change password

All other sessions are signed out.

Enable or disable 2FA

All other sessions are signed out.

Remove password

All other sessions are signed out.

Recover a passkey account

All previous sessions are signed out; the recovery session becomes the active session.

Destroy the vault

All sessions end and the account is closed.

#Common setup requirements

  • To add your first passkey, first set a password or enable 2FA.

  • To require a passkey at sign-in, register at least two passkeys.

  • To remove your password, keep at least one passkey or connected sign-in provider.

  • To remove a passkey, make sure the remaining methods still satisfy your passkey policy.

  • To disable 2FA or destroy the vault, set a password on the account.