Account and privacy
Passkeys, sessions and sign-in security
Add a passkey, connect a second email address, see every device your account is signed in on, and sign one out.
On this page
Everything on this page lives under Settings, Security. Nemi has no password, so what protects your account is the set of ways it can be opened: a Google account, one or more verified email addresses, and any passkeys you add. Keeping at least two of them is the single most useful thing you can do here.
Passkeys#
A passkey signs you in with Touch ID, Face ID, a Windows Hello prompt or a hardware key. It cannot be phished, because there is no code to read out to anybody, and it cannot be reused on a fake site.
Press Add passkey
Under Settings, Security, Passkeys.
Approve the system prompt
Your device or your password manager creates the key and keeps the private half.
Name it
Press the name in the list to rename it, so "MacBook" is not four rows called Passkey.
A passkey stored in iCloud Keychain or a password manager shows Synced in the list and works on your other devices. One created on a single laptop stays on that laptop, so add a second one somewhere else, or keep email sign-in as your way back in. Removing a passkey takes effect at once and cannot be undone; you simply add a new one.
Your Google account#
The Connected accounts block shows whether Google sign-in is attached, and to which address. Press Disconnect to remove it: your account and files are untouched, and you keep getting in with an email code or a passkey. Connecting reads only your name, email address and profile picture. A Google Calendar connection is a separate permission you grant separately in Calendar, and disconnecting Google here does not remove it.
More than one email address#
- 1
Press Add email
Under Connected emails.
- 2
Type the address and send the code
A six digit code arrives at that address.
- 3
Type the code
The address turns Verified and can be used to sign in.
- 4
Optionally make it primary
Press Make primary. Only a verified address can become the primary one, and the primary address is where account email is sent.
The primary address cannot be removed: promote another one first, then remove the old address. If Nemi says the address is already connected to a Nemi account, it is on a different account and has to be removed there first.
Devices you are signed in on#
Sessions and devices, on the Account tab, lists everywhere your account is currently open: the browser and operating system, roughly where it is, the IP address, when it was last active, and which row is the device you are reading this on. Sign out a single row with the button beside it, or use Sign out all other devices to clear everything except the one in front of you. It takes effect within a minute.
Your vault key#
If vault folders are switched on for you, the vault key sits at the bottom of this same page, because it is the same kind of thing as a passkey and it is lost the same way. It is worth reading If you lose your key before you need it: a lost vault key cannot be reset by us or by anybody else.
Is there two factor authentication?
A passkey already is a second factor: it is something you have plus your fingerprint, face or PIN. There is no separate authenticator app code.
I am signed out on every reload.
Usually a private window or a strict privacy extension blocking the session cookie. See Sign-in problems.
Somebody else is on my account.
Sign out all other devices, remove any passkey you do not recognise, and email support@nemilab.com with the time you noticed.
Related
Still stuck? Email support@nemilab.com and tell us what you were trying to do.