Docs
Home

Sign-in methods and two-factor

Manage your password, passkeys, Google, and two-factor authentication for your Monad account.

Your sign-in methods live in your account settings at onmonad.ai/account — not in an individual workspace. They apply to your whole account, everywhere you use Monad. Open the Sign-in methods section to manage them.

What you can set up

  • Password — add, change, or remove a password. When you set a new one, Monad checks it against a database of known-breached passwords and asks you to pick a different one if it's been exposed.
  • Passkeys — add a passkey for each device you use (your phone, your laptop, a security key). Give each one a name so you can tell them apart, and remove any you no longer use. Passkeys are the most secure and quickest way to sign in.
  • Google — link or unlink your Google account.

You can keep several methods at once and use whichever is handy. Monad won't let you remove your last sign-in method — you'd be locked out — so add a new one first if you want to replace the old one.

Two-factor authentication

Turn on two-factor authentication to add a second step when you sign in with your password:

  1. In Sign-in methods, start two-factor setup.
  2. Scan the QR code with an authenticator app (Apple Passwords, 1Password, Google Authenticator, and others all work), or type the secret in by hand.
  3. Enter the six-digit code to confirm.
  4. Save your recovery codes. You get a batch of ten single-use codes — keep them somewhere safe. They're your way back in if you lose your authenticator.

After that, signing in with your password asks for a code. Signing in with a passkey or Google doesn't — a passkey already counts as two factors.

You can view how many recovery codes you have left and regenerate a fresh batch at any time (regenerating replaces the old ones).

Always require a second factor

If you want the strongest protection, turn on Always require a second factor. Once it's on, every way of signing in has to clear a second factor — including Google, unless Google itself already verified one. Monad won't let you remove a method if doing so would leave you unable to meet that requirement. Your recovery codes are the only fallback.

When your workspace requires two-factor

A workspace owner can require everyone in that workspace to use two-factor. If you try to enter a workspace like that without one, Monad asks you to add a second factor before you go in. If you're setting up a brand-new factor at that moment from a password-only sign-in, you'll also confirm it with a link sent to your email — a safety step so only you can add it.

A note on passkeys

Passkeys are tied to Monad's web address. Passkeys you created on an older, workspace-specific address won't carry over — just add a fresh passkey on your device from this page and you're set.