Your account
Hiraiship has no passwords. You sign in with your email address and a code we send to it, and you can add a second code from an authenticator app.
Signing in
Enter your email
On the sign-in page, enter your email address and choose Continue with email.
Enter the code
We email you a 6-digit code. It expires after 10 minutes and works once. After three wrong tries it stops working: ask for a new one with Resend code.
There's no separate sign-up. The first code sent to an address creates its account, and you're asked for the name your teammates will see; you can skip it and change it later in Account settings → Profile. A personal workspace is created for you at the same time.
No code?
Check your spam folder. An address receives at most 12 codes in 24 hours: past that, no email is sent until the oldest one is a day old.
Two-factor authentication
With two-factor authentication on, signing in also asks for a code from an authenticator app (1Password, Google Authenticator, Authy…) after the emailed one. Someone who gets into your inbox still can't sign in.
Turning it on
- Open Account settings → Security and choose Set up two-factor.
- Scan the QR code with your authenticator app, or enter the key shown under it.
- Save the 10 backup codes. They're shown once.
- Enter the code your app shows and choose Turn on.
Turning it on signs you out everywhere else: on your other browsers, sign in again with both codes.
Signing in with it
After the emailed code, enter the 6-digit code from your app. A code is accepted once: if you just used it, wait for the next one. Without your device, choose Use a backup code instead; each backup code works once.
After five wrong codes, the sign-in is cancelled and you start again from your email.
Keep your backup codes
Store them in a password manager or somewhere offline. Without your device, they're the only way to finish signing in. To get a new set (the old one stops working), choose New backup codes in Account settings → Security.
Turning it off
In Account settings → Security, choose Turn off and enter a code from your app or a backup code.
Signing in again for sensitive actions
Some actions need a sign-in from the last 10 minutes:
- setting up, turning off or renewing two-factor authentication;
- creating an API key;
- transferring a workspace's ownership.
If yours is older, the dashboard asks you to sign in again first. There's no password to retype: a new emailed code (and your authenticator code) does it.
Sessions
Account settings → Security lists every browser and CLI login signed in to your account. Sign out of any you don't recognize, or of all of them but the current one.