Skip to main content

Sign-in and sessions

This page explains how the platform protects your account, and what you can do to protect it yourself. To sign in for the first time, see Sign in.

Your identity lives with your sign-in provider

Most people sign in through an identity provider: GitLab, GitHub, Google or your organization's single sign-on (Okta, Entra ID, Keycloak and others). The platform never sees your password for that provider. It only receives confirmation that you signed in.

That means your provider's security is your account's security:

  • Turn on two-factor authentication at your provider. The platform relies on your provider for it and does not have a separate second factor.
  • Change your password at the provider, not in Labs.
  • If your organization disables your provider account, you can no longer sign in to Labs either. Sessions that are already open continue until they end or are logged out, so also use Log out everywhere else.

Where the platform offers username and password sign-in, repeated wrong passwords temporarily lock further attempts, both for the account and for the network they come from. These accounts have no second factor on the platform, so use a long, unique password.

How long you stay signed in

Session lengthA session ends after at most 7 days, however active you are. Then you sign in again
Changes to your accessNew admin rights, a new plan or a new group membership apply from your next sign-in

Every change is checked

Every request that changes something (deploying, deleting, sharing, changing a setting) must carry a secret token tied to your session. A page on another website cannot make your browser act on your behalf, even while you are signed in. If a change fails with "Invalid or missing CSRF token", reload the page and try again.

See and end your sessions

Account Settings → Security shows:

Active sessionsEvery browser signed in to your account. Yours is marked This device
Recent loginsYour latest sign-ins
MCP clientsEvery AI assistant connected to your account, marked Live or Idle
  • Log out ends one other session on its next request.
  • Log out everywhere else ends all of them except yours.
  • Disconnect on an MCP client revokes that assistant's access. See How MCP connections are secured.
Active sessions with This device badge and Log out buttons, Log out everywhere else, Recent logins and the MCP clients list.

If you think someone else has access

Work through these in order:

  1. Account Settings → Security → Log out everywhere else.
  2. Disconnect every MCP client you do not recognise.
  3. Change your password, and turn on two-factor, at your sign-in provider. Ending sessions does not change the credential that created them.
  4. Account Settings → SSH keys: switch off or delete any key you do not recognise. Keys reach labs at deploy, so then redeploy your labs.
  5. Devices: delete any device you do not recognise. Its tunnel stops working immediately. See Devices.
  6. Check what ran: History and safety shows every action an AI assistant took.
  7. Tell your platform administrator.

Support access

Platform administrators can open your labs and resources to help you, and can view the dashboard as you (impersonation) to see what you see. Administrators must have signed in recently to do this, and every start and end is recorded with who did it and when. See Roles and permissions.

Next steps