Manage your account security
Open Account settings in the Ravenstash app to review your personal details and every way into your account.
What each section controls
Section titled “What each section controls”| Section | What you manage there |
|---|---|
| Profile | Your name, phone number, email address, and connected Google or GitHub accounts. |
| Security | Passkeys, password, authenticator app, recovery codes, and whether each connected account may sign in. |
| Devices | Signed-in browsers and terminals approved with rvs auth login. |
| Tokens | Secret values used by package tools and automation. These are separate from web sign-in. |
Understand the Security overview
Section titled “Understand the Security overview”Security settings groups your choices into three ways to sign in:
- Passkeys — sign in with your device unlock, fingerprint, face, or security key.
- Password — your Ravenstash email and password.
- Linked-accounts — Google and GitHub accounts connected to Ravenstash.
The message at the top reflects the least-protected way currently allowed into your account. Improving one sign-in choice does not protect another automatically, so review all three areas.
Allow a connected account to sign in
Section titled “Allow a connected account to sign in”Connect or disconnect Google and GitHub accounts from Profile. Then open Security and use Allow sign-in for each connected account.
A newly connected account is allowed to sign in by default. Turn Allow sign-in off if you want to keep the connection only for confirming account changes or future integrations.
Turning sign-in off does not disconnect the account. It can still help confirm an important change while you are already signed in, but nobody can use it to start a new Ravenstash sign-in.
Ravenstash may ask you to confirm before connecting, disconnecting, or changing sign-in access. It also prevents you from removing your last working way into the account.
Protect sign-in with another step
Section titled “Protect sign-in with another step”Adding a passkey or authenticator automatically protects password sign-in. If Google or GitHub sign-in is enabled, you can choose Require verification step from the security overview or manage Linked-account two-step verification under Advanced sign-in settings.
When that setting is on, signing in with Google or GitHub is followed by a Ravenstash passkey or authenticator check. Ravenstash does not rely on whether Google or GitHub asked for its own extra check.
MFA stance
Section titled “MFA stance”The security banner shows the least-protected sign-in method currently enabled on your account. These four tiers progress from the weakest stance to the strongest.
-
Tier 1 · Lowest protection
Needs protection
No second verification step has been set. Your account is at risk.
-
Tier 2 · Provider managed
Protected by your linked-account
Your weakest sign-in relies on the security configured in an enabled Google or GitHub account. Requiring a Ravenstash verification step strengthens linked-account sign-in.
-
Tier 3 · Fully enforced
Two-step verification fully enforced
All sign-in methods are protected by another verification step.
-
Tier 4 · Advanced
Passwordless Passkeys protection Advanced users
Password and linked-account sign-in are disabled, so you can sign in only with a passkey. This phishing-resistant stance carries a higher lockout risk: losing every passkey and your offline recovery codes can permanently lock you out of the account.
Manage your password
Section titled “Manage your password”Use Change password in the Password area. Changing your password signs out other browsers that depended on the old password while keeping the browser making the change available.
Password controls are also available under Advanced sign-in settings:
- Enable password sign-in for an account that currently signs in without one.
- Activate passwordless sign-in by removing the password.
Removing a password is allowed only when another reliable way in remains: an enabled Google or GitHub sign-in, or at least two passkeys. Ravenstash replaces your recovery codes during this change. Save the new codes before completing it.
Confirm an important change
Section titled “Confirm an important change”If Ravenstash needs fresh proof, it opens the full-page Confirm it’s you view, shows the signed-in account and action, and focuses on the best available choice: passkey, Google, password, then authenticator. GitHub is offered only as a last resort for a passwordless GitHub-only account with no local verification method. Select Try another way to see the other available choices; the link remains available even when only one normal method exists so recovery help is reachable.
The recovery option is deliberately less prominent. Open Try another way, then use Can’t use any of these? only when the normal choices are unavailable. If recovery codes exist, one can confirm the action. Without recovery codes, a password-only account is directed to password reset; a linked-account-only account is directed to Ravenstash support.
Too many attempts can temporarily pause an action. Follow the wait time in the error message before trying again; repeated retries do not shorten the pause.
Sign out browsers and devices
Section titled “Sign out browsers and devices”Use Devices to review active browsers and terminals:
- Sign out a browser you no longer recognize or use.
- Disconnect a terminal that was approved through
rvs auth login. - If you changed or lost a sign-in method, review this list after securing the account.
Package managers and build systems do not use your passkey or account password. They use separate automation tokens.
Next, read Passkeys and authenticator apps or Recovery codes and account recovery.

