Documentation
Sign inGet started

Login, password, and MFA

Use your security settings to change your password, manage multi-factor authentication (MFA), and review active sessions. For API access, see Authentication & API keys.

Signing in

You sign in to the Bird dashboard with an emailed sign-in link or six-digit code, your email address and password, or a connected Google or GitHub account. If MFA is enabled, complete the prompt with a passkey, an authenticator-app code, an SMS code, or a recovery code before the session starts.

Your password

Passwords must be at least 12 characters. Bird does not require a particular mix of character types, so a long passphrase works well. Bird also rejects new passwords that appear in known data breaches.
  • Change or set your password under your profile's Security settings in the dashboard. If your account already has a password, enter it to authorize the change. A passwordless account can set its first password without a current one.
  • Forgot it? Use the Forgot password link on the login page. Bird emails you a reset link that's valid for a short window and works only once.
Resetting your password invalidates all active sessions. Changing your password while signed in keeps the current session and signs out your other sessions.

Multi-factor authentication (MFA)

MFA adds another check at login so a stolen password alone is not enough to access your account. Bird supports these methods:
  • Authenticator app (TOTP): six-digit codes from a standard authenticator app.
  • SMS codes: a six-digit code sent to your enrolled phone number.
  • Passkeys: a device-bound or synced credential that uses your device's screen lock, fingerprint, or face recognition.

Enabling an authenticator app

  1. Open your profile's Security settings in the dashboard.
  2. Choose to add an authenticator app. Bird shows a QR code (and the secret as text, if you prefer to type it).
  3. Scan the QR code with your authenticator app, then enter the six-digit code it generates to confirm.
When you first enable MFA, Bird provides recovery codes. Store them in a password manager or another secure location. Each code works once. Regenerating the set invalidates all previous codes.

Removing a factor

You can remove an enrolled factor from the same Security settings. Removing the last verified factor disables MFA for the account.

Social login (Google and GitHub)

You can sign up for and sign in to Bird with a Google or GitHub account instead of a password. If a social account's verified email matches an existing Bird account, signing in links the two. Bird emails the account owner after the link is created. You can also connect or disconnect Google and GitHub from your existing account under your profile's Security settings.

Active sessions

Your profile's Active sessions page lists device and browser details and marks the current session. Sign out an unrecognized session or sign out all other sessions. Session invalidation takes effect immediately.
Sessions expire after 48 hours without activity or after 14 days, whichever comes first.

Security notification emails

Bird emails you when something security-relevant changes on your account, so unexpected activity is visible even if you weren't the one acting:
  • Password changed: sent after a password change or reset.
  • MFA enabled: sent when two-factor authentication is first enabled on your account.
  • Social account linked: sent when a Google or GitHub identity is connected to your account.
If you receive one of these and didn't make the change, reset your password immediately and review your active sessions and the audit log.

Next steps