← sizuq

Guide

Keeping the account yours

Passkeys, connected sign-in identities, Recovery Email, sessions, and why sizuq sometimes asks you to confirm you are still you.

Passkeys

A passkey is the fingerprint, face or screen lock your device already uses, standing in for a password. It never leaves the device, so there is nothing to leak, reuse or be phished out of you.

Add more than one when that matches how you use your devices. Each passkey is listed separately, but multiple passkeys still belong to one Passkey proof family for high-assurance actions.

Your passkeys

Connected sign-in identities

Apple, Google and X can be connected to the same sizuq account as independent sign-in routes. sizuq keys each connection by the provider and its immutable account subject, not by the email address the provider happens to return.

Manage sign-in connections

Why you are asked to confirm again

Some actions ask you to prove who you are again even though you are already signed in. A browser left open can be inherited by whoever is sitting in front of it, so credential and destructive changes require fresh proof rather than merely a valid session.

Asked for beforeWhy
Scheduling account deletionIt starts a destructive 30-day lifecycle and requires two independent fresh strong proof families
Changing Recovery Email or sign-in credentialsIt changes a route back into the account
Adding or removing a passkey or OAuth identityIt changes who can sign in
Signing out every other sessionIt changes account access across devices
Exporting your dataIt hands back everything at once

Fresh A1 confirmation can come from a Passkey, a connected Apple/Google/X identity, or a retained legacy password credential. TOTP and TOTP recovery codes are no longer supported by sizuq.

A deletion request signs out every session and fixes a 30-day deadline. Before that deadline, the same account can be restored by a Passkey, Apple, Google or X credential that already existed when deletion was requested. A Recovery Email that was already verified at that moment can also cancel deletion after its one-time recovery link and an explicit Restore action. Recovery Email restoration keeps the session restricted and does not count as an A1/A2 proof.

Sessions

Security settings list the current browser, other live browser sessions and native-app sessions. You can revoke another session individually, or confirm again and sign out every other session at once.

Manage sessions

Recent activity

Settings keeps a short history of sign-ins and security changes, so an attempt you do not recognise is visible rather than silent. Historical TOTP events may remain in that audit history even though TOTP itself has been retired.

Next: your data, and leaving