Secure your account

Maintain a strong password, enable two-factor sign-in, keep verified contact channels, and control the sessions where your account is signed in.

For
Everyone
Reading time
10 min
Updated
August 29, 2026

Before you start

  • A signed-in account and its current password; every security change re-verifies the password.
  • Access to the inbox or phone that receives verification codes.

You are done when

  • The Security section shows the intended password change date and two-factor state.
  • Contact channels show Verified, and Active sessions lists only sessions you recognize.

If something goes wrong

  • If you suspect the password is exposed, change it immediately; the change signs out every session, so sign in again everywhere.
  • If a verification code does not arrive, use the resend action. Deliveries are limited per day, and only the newest code stays valid.
  • If you cannot complete two-factor sign-in, use the recovery action on the sign-in page or contact the facility administrator.

Keep the password strong

  1. Open Account settings and choose Change password

    Enter the current password, then the new password twice.

  2. Meet the policy

    Passwords need at least 10 characters using at least two character types: lowercase, uppercase, numbers, or symbols. The same floor applies everywhere a password is set.

  3. Expect a global sign-out

    A successful change revokes every active session, including other devices. Sign in again with the new password.

Use two-factor authentication

  1. Toggle two-factor authentication in Security

    Confirm the change with the current password; changing the second factor always requires the first one.

  2. Choose a delivery method at sign-in

    With two-factor enabled, sign-in asks where to send the verification code: the primary account email, a verified contact email, or a verified contact phone.

  3. Enter the code promptly

    A code expires after five minutes, and only the newest requested code is accepted. Use the resend action when it does not arrive.

Maintain contact channels

  1. Add or update the contact email and phone

    Each change requires the current password. Mirket sends a verification code to the new destination, and the channel stays Not verified until you enter it.

  2. Verify before relying on a channel

    Only verified channels can receive two-factor codes, so verify immediately after adding one.

  3. Remove channels you no longer control

    Removal also requires the current password and takes the channel out of recovery and verification flows.

Audit active sessions

  1. Open Active sessions in Security

    Each entry shows when it signed in, when it was last active, and marks the current one as This session.

  2. Sign out sessions you do not recognize

    Sign out a single session, or use Sign out other sessions to keep only the current one. Revoked sessions must sign in again.

  3. Follow up on suspicious sessions

    After revoking an unknown session, change the password and confirm that the contact channels are still yours.

Continue with