Guide
Keeping the account yours
Passkeys, connected sign-in identities, Recovery Email, sessions, and why sizuq sometimes asks you to confirm you are still you.
Passkeys
A passkey is the fingerprint, face or screen lock your device already uses, standing in for a password. It never leaves the device, so there is nothing to leak, reuse or be phished out of you.
Add more than one when that matches how you use your devices. Each passkey is listed separately, but multiple passkeys still belong to one Passkey proof family for high-assurance actions.
Your passkeysConnected sign-in identities
Apple, Google and X can be connected to the same sizuq account as independent sign-in routes. sizuq keys each connection by the provider and its immutable account subject, not by the email address the provider happens to return.
Manage sign-in connectionsWhy you are asked to confirm again
Some actions ask you to prove who you are again even though you are already signed in. A browser left open can be inherited by whoever is sitting in front of it, so credential and destructive changes require fresh proof rather than merely a valid session.
| Asked for before | Why |
|---|---|
| Scheduling account deletion | It starts a destructive 30-day lifecycle and requires two independent fresh strong proof families |
| Changing Recovery Email or sign-in credentials | It changes a route back into the account |
| Adding or removing a passkey or OAuth identity | It changes who can sign in |
| Signing out every other session | It changes account access across devices |
| Exporting your data | It hands back everything at once |
Fresh A1 confirmation can come from a Passkey, a connected Apple/Google/X identity, or a retained legacy password credential. TOTP and TOTP recovery codes are no longer supported by sizuq.
A deletion request signs out every session and fixes a 30-day deadline. Before that deadline, the same account can be restored by a Passkey, Apple, Google or X credential that already existed when deletion was requested. A Recovery Email that was already verified at that moment can also cancel deletion after its one-time recovery link and an explicit Restore action. Recovery Email restoration keeps the session restricted and does not count as an A1/A2 proof.
Sessions
Security settings list the current browser, other live browser sessions and native-app sessions. You can revoke another session individually, or confirm again and sign out every other session at once.
Manage sessionsRecent activity
Settings keeps a short history of sign-ins and security changes, so an attempt you do not recognise is visible rather than silent. Historical TOTP events may remain in that audit history even though TOTP itself has been retired.
Next: your data, and leaving