Skip to main content

Overview

Configure security settings to protect your StatusStack account and organization.

Passkeys

Passkeys let you sign in with a fingerprint, face scan, screen lock, or hardware security key. Customer dashboard and MSP Console; no plan gate. A successful passkey login satisfies 2FA.
You’ll need an account password to add a passkey. Manage them at SettingsProfile SettingsPasskeys (customers) or SettingsSecurity (MSP). Bound to statusstack.com — not white-label custom domains, not Statamic CMS admin.

Add a passkey

1

Open the Passkeys manager

Use the path for your interface above.
2

Confirm your password

Re-enter your current account password.
3

Add Passkey

Complete the browser or OS prompt.
See Authentication for sign-in behavior and limits.

Two-Factor Authentication

Enable 2FA

1

Open Security Settings

SettingsSecurityTwo-Factor Authentication
2

Choose Method

  • Authenticator app (recommended)
  • SMS
3

Scan QR Code

Use Google Authenticator, Authy, or 1Password
4

Save Backup Codes

Store securely for account recovery

Session Management

Active Sessions

View and manage logged-in devices: SettingsSecurityActive Sessions
Revoke suspicious sessions immediately

Login History

Track authentication events:
  • Successful logins
  • Failed login attempts
  • Password changes
  • 2FA events
  • Passkey registrations and logins
  • OAuth connections
Access: SettingsSecurityLogin History

API Keys

Manage API access tokens:
1

Create API Key

SettingsAPI Keys“Create Key”
2

Set Permissions

  • Read-only
  • Read/Write
  • Admin
3

Copy Token

Shown once - store securely
4

Revoke When Done

Delete unused keys regularly

Security Best Practices

  • 12+ characters
  • Mix of types
  • Unique per site
  • Password manager
  • Phishing-resistant login
  • Satisfies 2FA when sign-in succeeds
  • Keep a password as a backup
Required for:
  • Owners and Admins
  • Production access
  • Recommended for all
  • Check active devices
  • Revoke unknown sessions
  • Verify locations
  • Quarterly rotation
  • Delete unused keys
  • Use least privilege

Next Steps

Authentication

Login methods, passkeys, and SSO

Team Management

Manage team access