Skip to content

Your account

Hiraiship has no passwords. You sign in with your email address and a code we send to it, and you can add a second code from an authenticator app.

Signing in

  1. Enter your email

    On the sign-in page, enter your email address and choose Continue with email.

  2. Enter the code

    We email you a 6-digit code. It expires after 10 minutes and works once. After three wrong tries it stops working: ask for a new one with Resend code.

There's no separate sign-up. The first code sent to an address creates its account, and you're asked for the name your teammates will see; you can skip it and change it later in Account settings → Profile. A personal workspace is created for you at the same time.

No code?

Check your spam folder. An address receives at most 12 codes in 24 hours: past that, no email is sent until the oldest one is a day old.

Two-factor authentication

With two-factor authentication on, signing in also asks for a code from an authenticator app (1Password, Google Authenticator, Authy…) after the emailed one. Someone who gets into your inbox still can't sign in.

Turning it on

  1. Open Account settings → Security and choose Set up two-factor.
  2. Scan the QR code with your authenticator app, or enter the key shown under it.
  3. Save the 10 backup codes. They're shown once.
  4. Enter the code your app shows and choose Turn on.

Turning it on signs you out everywhere else: on your other browsers, sign in again with both codes.

Signing in with it

After the emailed code, enter the 6-digit code from your app. A code is accepted once: if you just used it, wait for the next one. Without your device, choose Use a backup code instead; each backup code works once.

After five wrong codes, the sign-in is cancelled and you start again from your email.

Keep your backup codes

Store them in a password manager or somewhere offline. Without your device, they're the only way to finish signing in. To get a new set (the old one stops working), choose New backup codes in Account settings → Security.

Turning it off

In Account settings → Security, choose Turn off and enter a code from your app or a backup code.

Signing in again for sensitive actions

Some actions need a sign-in from the last 10 minutes:

  • setting up, turning off or renewing two-factor authentication;
  • creating an API key;
  • transferring a workspace's ownership.

If yours is older, the dashboard asks you to sign in again first. There's no password to retype: a new emailed code (and your authenticator code) does it.

Sessions

Account settings → Security lists every browser and CLI login signed in to your account. Sign out of any you don't recognize, or of all of them but the current one.