Skip to content

Manage your account security

Open Account settings in the Ravenstash app to review your personal details and every way into your account.

Section What you manage there
Profile Your name, phone number, email address, and connected Google or GitHub accounts.
Security Passkeys, password, authenticator app, recovery codes, and whether each connected account may sign in.
Devices Signed-in browsers and terminals approved with rvs auth login.
Tokens Secret values used by package tools and automation. These are separate from web sign-in.

Security settings groups your choices into three ways to sign in:

  1. Passkeys — sign in with your device unlock, fingerprint, face, or security key.
  2. Password — your Ravenstash email and password.
  3. Linked-accounts — Google and GitHub accounts connected to Ravenstash.

The message at the top reflects the least-protected way currently allowed into your account. Improving one sign-in choice does not protect another automatically, so review all three areas.

Connect or disconnect Google and GitHub accounts from Profile. Then open Security and use Allow sign-in for each connected account.

A newly connected account is allowed to sign in by default. Turn Allow sign-in off if you want to keep the connection only for confirming account changes or future integrations.

Turning sign-in off does not disconnect the account. It can still help confirm an important change while you are already signed in, but nobody can use it to start a new Ravenstash sign-in.

Ravenstash may ask you to confirm before connecting, disconnecting, or changing sign-in access. It also prevents you from removing your last working way into the account.

Adding a passkey or authenticator automatically protects password sign-in. If Google or GitHub sign-in is enabled, you can choose Require verification step from the security overview or manage Linked-account two-step verification under Advanced sign-in settings.

When that setting is on, signing in with Google or GitHub is followed by a Ravenstash passkey or authenticator check. Ravenstash does not rely on whether Google or GitHub asked for its own extra check.

The security banner shows the least-protected sign-in method currently enabled on your account. These four tiers progress from the weakest stance to the strongest.

  1. Tier 1 · Lowest protection

    Needs protection

    No second verification step has been set. Your account is at risk.

  2. Tier 2 · Provider managed

    Protected by your linked-account

    Your weakest sign-in relies on the security configured in an enabled Google or GitHub account. Requiring a Ravenstash verification step strengthens linked-account sign-in.

  3. Tier 3 · Fully enforced

    Two-step verification fully enforced

    All sign-in methods are protected by another verification step.

  4. Tier 4 · Advanced

    Passwordless Passkeys protection Advanced users

    Password and linked-account sign-in are disabled, so you can sign in only with a passkey. This phishing-resistant stance carries a higher lockout risk: losing every passkey and your offline recovery codes can permanently lock you out of the account.

Use Change password in the Password area. Changing your password signs out other browsers that depended on the old password while keeping the browser making the change available.

Password controls are also available under Advanced sign-in settings:

  • Enable password sign-in for an account that currently signs in without one.
  • Activate passwordless sign-in by removing the password.

Removing a password is allowed only when another reliable way in remains: an enabled Google or GitHub sign-in, or at least two passkeys. Ravenstash replaces your recovery codes during this change. Save the new codes before completing it.

If Ravenstash needs fresh proof, it opens the full-page Confirm it’s you view, shows the signed-in account and action, and focuses on the best available choice: passkey, Google, password, then authenticator. GitHub is offered only as a last resort for a passwordless GitHub-only account with no local verification method. Select Try another way to see the other available choices; the link remains available even when only one normal method exists so recovery help is reachable.

The recovery option is deliberately less prominent. Open Try another way, then use Can’t use any of these? only when the normal choices are unavailable. If recovery codes exist, one can confirm the action. Without recovery codes, a password-only account is directed to password reset; a linked-account-only account is directed to Ravenstash support.

Too many attempts can temporarily pause an action. Follow the wait time in the error message before trying again; repeated retries do not shorten the pause.

Use Devices to review active browsers and terminals:

  • Sign out a browser you no longer recognize or use.
  • Disconnect a terminal that was approved through rvs auth login.
  • If you changed or lost a sign-in method, review this list after securing the account.

Package managers and build systems do not use your passkey or account password. They use separate automation tokens.

Next, read Passkeys and authenticator apps or Recovery codes and account recovery.