> ## Documentation Index
> Fetch the complete documentation index at: https://docs.begin.eu/llms.txt
> Use this file to discover all available pages before exploring further.

# Secure your account

> Manage your passkeys, sign out other devices and revoke connected AI clients.

<img src="https://mintcdn.com/beginltd/zeGlKdCOG-PEugD7/images/cover/settings-account-security-light.png?fit=max&auto=format&n=zeGlKdCOG-PEugD7&q=85&s=2cdcb70f024eefb27d5fac55a83d01cd" alt="A security card showing the current Safari session and a MacBook Pro passkey" className="block dark:hidden" noZoom width="1152" height="616" data-path="images/cover/settings-account-security-light.png" />

<img src="https://mintcdn.com/beginltd/zeGlKdCOG-PEugD7/images/cover/settings-account-security-dark.png?fit=max&auto=format&n=zeGlKdCOG-PEugD7&q=85&s=4c7c0b638728741b75985bc37fb0c7d5" alt="A security card showing the current Safari session and a MacBook Pro passkey" className="hidden dark:block" noZoom width="1152" height="616" data-path="images/cover/settings-account-security-dark.png" />

Open **Settings → Security** to check where you are signed in, manage passkeys and remove external AI clients from your account. These controls secure your account; they do not change the access roles you give your team.

<img src="https://mintcdn.com/beginltd/O3eNHOhbC75NvE_t/images/articles/settings/settings-account-security-screen-light.png?fit=max&auto=format&n=O3eNHOhbC75NvE_t&q=85&s=7ed21c2ca98a72a4e8be8c4a8b03d5be" alt="Security settings showing active sessions and the current device" className="block dark:hidden" width="2944" height="1840" data-path="images/articles/settings/settings-account-security-screen-light.png" />

<img src="https://mintcdn.com/beginltd/O3eNHOhbC75NvE_t/images/articles/settings/settings-account-security-screen-dark.png?fit=max&auto=format&n=O3eNHOhbC75NvE_t&q=85&s=9ec8cb87be1969fb51e60064d72b1c04" alt="Security settings showing active sessions and the current device" className="hidden dark:block" width="2944" height="1840" data-path="images/articles/settings/settings-account-security-screen-dark.png" />

## Sign out other devices

**Active sessions** lists signed-in browsers and devices, their IP addresses and recent activity. **This device** marks the session you are using now.

Choose **Revoke** beside an unfamiliar or unused session. To sign out everywhere else, choose **Revoke all other sessions** and confirm. Your current session stays signed in.

If a phone or laptop is lost, revoke its session from a device you still control. Also remove any passkey you no longer want that device to use.

## Add and manage passkeys

<Steps>
  <Step title="Name the passkey">
    Choose **Add passkey** and use a name you will recognise, such as your device’s name.
  </Step>

  <Step title="Complete the device prompt">
    Follow the fingerprint, face, PIN or security-key prompt. If Begin asks you to verify your
    account again, complete that check.
  </Step>

  <Step title="Check it was added">
    Confirm the new passkey appears in the list. You can rename it later to keep devices
    recognisable.
  </Step>
</Steps>

Begin has no password and no separate two-factor code. Sign-in is a one-time code to your verified email or phone, a passkey, or a linked social account; a passkey is the strongest option.

Adding a passkey requires a browser or device that supports passkeys. Remove an unused passkey from its row and confirm. Begin prevents you from removing your last sign-in method; keep another working method before removing one you rely on.

## Revoke connected AI clients

**Connected MCP clients** lists external tools authorised through Begin MCP. Check the client name and any workspace shown, then choose **Revoke** to disconnect it. You can also revoke all connected clients.

Revocation takes effect immediately. It does not delete information the external tool has already received. To reconnect, follow [the Begin MCP setup guide](/for-managers/integrations/mcp) and authorise the client again.

Session, passkey and MCP grants are self-service and account-scoped. Revoke-all-other-sessions uses the server’s current-session identity. Passkey deletion counts email, phone, linked social accounts and passkeys as sign-in methods; there is no password and no TOTP or SMS second factor to enable. This page does not manage another person’s credentials or workplace clocking terminals.

## Next

<Columns cols={2}>
  <Card title="Update your personal profile" icon="user" href="/for-managers/settings/personal-profile">
    Keep your sign-in contacts current.
  </Card>

  <Card title="Download your personal data" icon="download" href="/for-managers/settings/privacy-and-data">
    Download your personal records.
  </Card>
</Columns>

## Still need help?

<Columns cols={2}>
  <Card title="Contact support" icon="envelope" href="mailto:support@heybegin.eu">
    Email the Begin team and we'll get back to you.
  </Card>

  <Card title="Ask Begin AI" icon="comment-dots" href="?assistant=open">
    Open the AI assistant and get instant answers based on these docs.
  </Card>
</Columns>
