Password & Security

Sign in, change your password, set up two-factor authentication and passkeys, and recover access if you're locked out.

Password & Security

Your password and two-factor settings live under Settings → Password & Security, in the Personal group. Open Settings from the gear at the bottom of the sidebar; the page is available to everyone, whether or not you administer an organization.

The Password & Security settings page (click to zoom)

Signing In

Enter your email address and click Continue, then choose how to sign in:

  • Send Code emails you a 6-digit sign-in code. Type it in, or click the button in the email instead. The code and link expire after 15 minutes and work only once — use Send another if it doesn't arrive.
  • Use Password asks for your password, then Login.
  • Passkey — if you've added one, your browser offers it when you click into the email field. Choosing it signs you in straight away, with no password and no second step.

If you've set up two-factor authentication, you'll confirm it's you next (see below). If you were invited to an organization, your account is created when you accept the invitation and set a password.

Changing Your Password

Changing your password takes two steps: prove it's you, then set the new one.

  1. Enter your current password and click Change password. If it's wrong you'll see Incorrect password. Please try again.
  2. A dialog opens for the new password. Type it twice — the second field must match — and confirm.
  3. You'll see a confirmation once the change is saved. Use the new password the next time you sign in.

What Makes a Valid Password

The new-password field checks your password as you type, so you can see what's still missing before you submit:

  • At least 12 characters
  • Strong enough password — Cardinal rates how hard the password would be to guess. Common words, names, dates, and predictable patterns score low.

While the password is too weak, you'll also see a warning and suggestions for improving it. A longer phrase of unrelated words is usually the easiest way to pass.

If You Don't Remember Your Password

You can still sign in with an emailed code — choose Send Code instead of Use Password. To set a new password, click Use Password on the sign-in page, then Forgot password?, and enter your email. We'll send a reset link to the address on your account.

Two-Factor Authentication

Two-factor authentication adds a second check after your password or emailed code, so a stolen password alone can't open your account. Manage it in the Two-factor authentication section of Settings → Password & Security.

Your two-factor methods and recovery codes (click to zoom)

Adding a Method

Click + Add method and choose one:

Passkey

Uses Face ID, Touch ID, Windows Hello, or a security key — the fastest option where it's available. Give it a name, click Continue, and follow your device's prompt. If your browser doesn't support passkeys, the option isn't offered.

Authenticator App

Uses a 6-digit code from an app like 1Password or Google Authenticator. Name it, click Set up, then scan the QR code with your app — or, if you can't scan it, enter the key shown below the code. Type the 6-digit code your app shows and click Confirm.

Text Message

Texts a 6-digit code to your phone each time you sign in. Enter your number (US numbers only for now), click Send code, and type in the code you receive. It works on any phone but is less secure than a passkey or authenticator app. This number is used only for sign-in codes — it doesn't change the phone number on your profile.

Managing Your Methods

  • Each method shows its type, the date you added it, and when it was last used
  • Passkeys can be renamed with Rename — handy when you have one per device
  • Remove asks for your password before deleting the method. This can't be undone

Recovery Codes

Recovery codes are single-use backup codes for when you can't reach your usual method — a lost phone, say. The section shows how many unused codes you have left.

  • Click Regenerate and enter your password to get a new set of ten codes
  • The codes are shown only once — save them somewhere safe, such as your password manager, before clicking Done
  • Regenerating replaces your old codes; any you saved before stop working

Confirming It's You at Sign-In

Once you have a method set up, Cardinal asks for it each time you sign in with your password or an emailed code. Cardinal starts with the method you used last — for example, a 6-digit code from your authenticator app or your passkey — and offers the others on the same screen:

  • Use a passkey instead, or use an authenticator app code instead
  • Text a code to the phone you added
  • Use a backup code instead — enter one of your 8-character recovery codes

You only see the options you've set up.

When Your Organization Requires It

If your organization requires two-factor authentication and you haven't set it up, Cardinal walks you through adding an authenticator app right after you sign in. You can't use the rest of the app until it's done.

Locked Out?

If you've lost every method and your recovery codes, ask an Owner or Admin in your organization. From Settings → Organization → Users, they can open your profile and choose Reset MFA. That clears your methods and recovery codes, signs you out everywhere, and emails you — the next time you sign in, you'll set up a new method.

“You Don't Have Access to This Page”

You'll see this screen when you open something — a link to a property, lease, issue, or file, for example — that your role doesn't let you see. For your security it never confirms whether the item exists. Click Go to dashboard to carry on, and if you think you should have access, ask an administrator in your organization to grant it.