# Authentication

Tailglow supports email sign-in and passwords. Each browser keeps its own session, which you can
review or revoke from your profile.

## Email sign-in

Enter your email address and Tailglow emails you a sign-in link and an 8-character code. This
passwordless option is the default for new accounts.

- The link and the code only work in the browser where you asked for them. If you open the email on
  another device, such as your phone, type the code into the browser where you started.
- Both expire after 10 minutes and work once. Requesting a new email replaces the previous link and
  code.
- If you open the link in another tab of the same browser, the tab where you started shows that you
  are signed in, and you can close it.
- You can request up to 5 sign-in emails in 15 minutes, and up to 20 in a day.

## Password

Passwords are optional and must be at least 16 characters long. Use a password manager to generate
and store yours.

You must enable multi-factor authentication (MFA) before adding a password. To change your password,
open your profile's **Security** tab and provide a valid MFA code.

## Browser sessions

Signing in creates a separate session for that browser. Signing in somewhere new does not sign out
your other browsers, and closing a browser does not end its session.

Open **Profile** > **Security**, then find **Devices** to review active sessions and sign out a
specific browser. You can have up to 25 active browser sessions. If you exceed that limit, Tailglow
signs out the least recently active session. A session you have not used for six months, in a
browser or a terminal, ends on its own, and you sign in again there.

Clearing Tailglow site data signs out that browser locally. The session may remain listed in the
**Devices** section until you revoke it.

## CLI sessions

Approving a `tglow login` in the browser gives that terminal a session of its own. It appears under
**Devices** with a **CLI** label and the machine's name. Like a browser session, it can act in any of
your teams; it starts in the one you chose when you approved it. A CLI session carries the MFA
verification of the browser session that approved it.

CLI sessions are counted separately from browser sessions, up to 10 active at once; signing in from
another terminal beyond that ends the least recently used one. Revoking it under **Devices**,
signing out of every device, changing your password, resetting MFA, or running `tglow logout` in
that terminal ends it immediately.

A CLI session cannot change how your account signs in: MFA, passwords and sessions are managed
here, in the browser. See [CLI](/guides/cli#authenticating).

## Multi-factor authentication

Tailglow uses time-based one-time passwords (TOTP) for MFA. You will need an authenticator app that
can scan a QR code and generate six-digit codes.

### Set up MFA

1. Open **Profile** and select **Security**.
2. In **Multi-factor Authentication**, open the actions menu and select **Enable MFA**.
3. Scan the QR code with your authenticator app.
4. Click **Confirm MFA**.
5. Enter the six-digit code from your authenticator app and click **Submit**.
6. Save the backup codes, then click **I've copied my backup codes**.

Backup codes are shown only once. Store them somewhere secure, such as a password manager. Each code
can be used once, and Tailglow emails you when a backup code is used to sign in.

You can regenerate backup codes from **Profile** > **Security**. Regenerating them requires a valid
MFA code and invalidates the previous set.

### Disable MFA

You can disable MFA from **Profile** > **Security** with an authenticator code or backup code. If
password sign-in is enabled, disabling MFA also disables password sign-in. You can continue using
email sign-in. Disabling MFA also signs you out of every browser, including the one you are using.

### Team-required MFA

Team owners can require MFA for all members. If a team requires MFA, Tailglow prompts members to set
it up before they can access that team.

MFA verification applies to one browser session at a time.

## Sign out and security activity

Signing out normally ends only the current browser session. From **Profile** > **Security** you can:

- Use the **Devices** section to sign out another browser or every browser.
- Review authentication history, including the action, time, device, and IP address.

## Roles and permissions

Your role in each team determines which features and actions you can access. Team owners can manage
roles from **Team Settings** > **Roles**. See [Permissions](/guides/permissions) for how access levels
and role presets work.

Your selected team is specific to each browser, so another signed-in browser can remain on a
different team.
