Docs

Securing your account

Two-step verification with an authenticator app, recovery codes, changing your email, moving or re-linking your home computer, deleting the account.

Your Wilow account guards three things: the encryption key that every new device receives, the computer that runs your agents (your "home"), and the projects you share. This page covers the settings that protect it and what to do when something goes wrong. Everything here lives in Settings → Account.

Two-step verification

Turn it on and every sign-in asks for a 6-digit code from an authenticator app (Google Authenticator, 1Password, Authy and others) after your password. A password alone can then never open your account, pair a new device, move your home computer, change your email, share a project or delete the account.

  1. Settings → Account → Two-step verification → Turn on.
  2. Scan the QR code with your authenticator app, or type the key shown under it.
  3. Enter the first 6-digit code the app shows and press Confirm.
  4. Wilow shows eight recovery codes, once. Save them somewhere safe: a password manager, or paper in a drawer. Each works a single time.

Lost your phone?

On the sign-in code screen choose Lost your phone? Use a recovery code. A recovery code signs you in and removes the old authenticator, so you can set up a new one from Settings. Recovery codes stop working the moment two-step verification is turned off or a new set is generated.

Two-step verification is optional. Wilow suggests it once after setup and never nags again; you can turn it on or off at any time with a current code.

Your email addresses

Settings → Account → Email addresses. An account can have several addresses; one is the primary you sign in with. Add another email address emails a 6-digit code to the new address, and typing it in the app links it. Make primary switches the login address to any verified one; Remove drops an address as long as one remains, and removing the primary promotes the next verified address. Any linked address signs you in, and project invitations sent to any of them reach you. Collaborators keep seeing your name, not your address.

Your home computer

One computer runs your agents. If that computer dies, or you replace it, sign in on the new one and use Settings → Account → Move home to this computer (your password confirms it). The old computer is disconnected immediately; project files stay on its disk and are not copied.

If Wilow shows "This computer's Wilow identity no longer matches your account", the daemon on this computer is registered to a different account or its credentials were reset. Press Re-link this computer; it opens the same Move-home confirmation.

Deleting your account

  • Settings → Account → Danger zone → Delete account, then type your email to confirm.
  • Removed from the relay: your messages, device records, encryption-key wraps and project metadata. Not touched: files on your computer and anything in the accounts you connected (GitHub, Vercel, Google…).