Authentication

Authentication

Tailglow supports email sign-in and passwords. Each browser keeps its own session, which you can review or revoke from your profile.

Email sign-in

Enter your email address and Tailglow emails you a sign-in link and an 8-character code. This passwordless option is the default for new accounts.

  • The link and the code only work in the browser where you asked for them. If you open the email on another device, such as your phone, type the code into the browser where you started.
  • Both expire after 10 minutes and work once. Requesting a new email replaces the previous link and code.
  • If you open the link in another tab of the same browser, the tab where you started shows that you are signed in, and you can close it.
  • You can request up to 5 sign-in emails in 15 minutes, and up to 20 in a day.

Password

Passwords are optional and must be at least 16 characters long. Use a password manager to generate and store yours.

You must enable multi-factor authentication (MFA) before adding a password. To change your password, open your profile’s Security tab and provide a valid MFA code.

Browser sessions

Signing in creates a separate session for that browser. Signing in somewhere new does not sign out your other browsers, and closing a browser does not end its session.

Open Profile > Security, then find Devices to review active sessions and sign out a specific browser. You can have up to 25 active browser sessions. If you exceed that limit, Tailglow signs out the least recently active session. A session you have not used for six months, in a browser or a terminal, ends on its own, and you sign in again there.

Clearing Tailglow site data signs out that browser locally. The session may remain listed in the Devices section until you revoke it.

CLI sessions

Approving a tglow login in the browser gives that terminal a session of its own. It appears under Devices with a CLI label and the machine’s name. Like a browser session, it can act in any of your teams; it starts in the one you chose when you approved it. A CLI session carries the MFA verification of the browser session that approved it.

CLI sessions are counted separately from browser sessions, up to 10 active at once; signing in from another terminal beyond that ends the least recently used one. Revoking it under Devices, signing out of every device, changing your password, resetting MFA, or running tglow logout in that terminal ends it immediately.

A CLI session cannot change how your account signs in: MFA, passwords and sessions are managed here, in the browser. See CLI.

Multi-factor authentication

Tailglow uses time-based one-time passwords (TOTP) for MFA. You will need an authenticator app that can scan a QR code and generate six-digit codes.

Set up MFA

  1. Open Profile and select Security.
  2. In Multi-factor Authentication, open the actions menu and select Enable MFA.
  3. Scan the QR code with your authenticator app.
  4. Click Confirm MFA.
  5. Enter the six-digit code from your authenticator app and click Submit.
  6. Save the backup codes, then click I’ve copied my backup codes.

Backup codes are shown only once. Store them somewhere secure, such as a password manager. Each code can be used once, and Tailglow emails you when a backup code is used to sign in.

You can regenerate backup codes from Profile > Security. Regenerating them requires a valid MFA code and invalidates the previous set.

Disable MFA

You can disable MFA from Profile > Security with an authenticator code or backup code. If password sign-in is enabled, disabling MFA also disables password sign-in. You can continue using email sign-in. Disabling MFA also signs you out of every browser, including the one you are using.

Team-required MFA

Team owners can require MFA for all members. If a team requires MFA, Tailglow prompts members to set it up before they can access that team.

MFA verification applies to one browser session at a time.

Sign out and security activity

Signing out normally ends only the current browser session. From Profile > Security you can:

  • Use the Devices section to sign out another browser or every browser.
  • Review authentication history, including the action, time, device, and IP address.

Roles and permissions

Your role in each team determines which features and actions you can access. Team owners can manage roles from Team Settings > Roles. See Permissions for how access levels and role presets work.

Your selected team is specific to each browser, so another signed-in browser can remain on a different team.