Sign-in & security
Email verification, passwords, two-factor authentication and sessions.
Email verification#
After sign-up, Toolies emails you a six-digit code (valid 30 minutes) and a link (valid 24 hours). Either confirms your address. Five wrong codes cancel the code; ask for a new email from the verification page. If you mistyped your address, you can correct it there before verifying.
Password#
Passwords are 10 to 128 characters; a passphrase is easiest. To change it, open Account & security → Password and click Email me a link: the link is valid for one hour. Changing your password signs you out everywhere and disconnects every AI assistant, in case the old one leaked.
Forgot it? Click Forgot your password? on the login page.
Two-factor authentication#
Protect sign-ins with an authenticator app (Google Authenticator, 1Password, Authy…).
Start
In Account & security, find Two-factor authentication and click Set up authenticator.
Scan the QR code
Scan it with your authenticator app, or type the secret key.
Confirm
Enter the six-digit code from the app. From now on, Toolies asks for a code at each sign-in, and before sensitive actions such as deleting your account or transferring ownership.
Keep access to your authenticator app. If you lose it, write to your workspace administrator from your account’s email address.
To turn it off, click Turn off next to Authenticator app enabled, then confirm with your password and a code from the app. Sign-in then asks for your password only.
Sessions#
A sign-in lasts 7 days on a browser. Signing in again from the same browser replaces the previous session, and the log out button at the bottom of the sidebar ends it immediately.
Connected AI assistants#
See and disconnect the assistants that can access your workspace on the MCP page of the dashboard. See Permissions & security.