{% extends "base.html" %} {% block content %}

{{ current_user['username'] }}

Account security

Your authenticator protects local, LDAP and OpenID Connect sign-ins. Each change below requires a fresh code from your current authenticator.

Recovery codes

{{ remaining }} unused recovery codes remain.

{% if not remaining %}

Create recovery codes now so you can regain access if your authenticator is lost.

{% endif %}

Each code can be used once, after your normal sign-in, to enroll a new authenticator. Generating a new set invalidates previous recovery codes and signs out other sessions.

Change authenticator

Verify your current authenticator, then scan a new QR code. Your existing authenticator stays active until the new one is verified. Completing the change invalidates previous sessions and recovery codes.

A code already used to sign in cannot authorize another action. Wait for the next 30-second code if needed.

{% endblock %}