Settings
This page explains the Settings pages, where you manage your own account, and covers the recovery email, the display time zone, and why some changes ask for your password again.
The Settings pages
Settings is where you manage your account: how you sign in, how you are contacted, your API key, and deleting the account. It is a group of five pages. Click Settings near the bottom of the dashboard sidebar to show them, then click the page you want; each one has its own address, so you can also bookmark it. The same five pages are tabs along the top of every Settings page.
Each page shows its settings as boxes with the form already open. A box shows the current state on the right of its title (for example your email, or on / off). After you submit, the same page comes back with a message at the top saying whether it worked.
| Page | Address | Settings | Covered on |
|---|---|---|---|
| Account | /scanner/settings/account |
Recovery email, Time zone | this page |
| Sign-in & sessions | /scanner/settings/sign-in |
Change password, Session timeout | Password and sessions |
| Two-factor authentication | /scanner/settings/two-factor |
Authenticator app, Backup codes, Email sign-in codes | Two-factor authentication |
| API access | /scanner/settings/api-access |
Active key, Generate a key (or Regenerate key), Revoke key | API keys |
| Danger zone | /scanner/settings/danger-zone |
Delete account | Delete your account |
The old address /scanner/settings still works and opens the Account page.
Recovery email
Your recovery email is the address EyalSec uses to reach you about your account: password reset codes, email sign-in codes and security notices go there. It is on the Account page, and the box shows the current address, not set, or pending: followed by an address that is waiting for confirmation.
To set or change it:
- Open Settings > Account and go to Recovery email.
- Type the new address in Email.
- Enter your password under Confirm password, and a 2FA code if the field is shown (see Re-entering your password).
- Click Save email.
The new address does not take effect yet. EyalSec emails a confirmation link to the new address, and the change happens when you click it; this proves the inbox is yours. Until then your old address stays in place, and it gets a notice that a change was requested.
- Open the link in a browser where you are signed in to this account. It is valid for 24 hours.
- Only one change can wait at a time. A new request replaces the pending one, but you must wait 5 minutes after one confirmation email before asking for another.
- If the address has been taken by another account in the meantime, the confirmation is refused; choose a different address.
To remove the address, clear the field and save. That happens immediately, cancels any pending change, and turns off email sign-in codes, which need an address to send to. Without a recovery email, Forgot password cannot reach you, so keep a working one on file.
Time zone
Time zone sets the zone that times on the Events, Activity and Dashboard pages are shown in. Auto (detect from browser), the default, uses whatever zone your browser is set to.
To change it, open Settings > Account, pick a zone under Display times in, and click Save time zone. Pick Auto to go back to following the browser. This only changes how times are displayed; it never changes stored data, and it does not ask for your password.
Re-entering your password
Some changes ask you to type your current password even though you are signed in. This stops anyone who finds your computer unlocked from quietly taking over or weakening your account.
| Action | Password | 2FA code (when an authenticator app is on) |
|---|---|---|
| Change recovery email | yes | yes |
| Change session timeout | yes | yes |
| Generate or regenerate an API key | yes | yes |
| Change password | current password | no |
| Turn the authenticator app or email sign-in codes on or off | yes | no |
| Regenerate backup codes | yes | no |
| Revoke the API key | yes | no |
| Delete the account | yes | no |
The 2FA code can be the current code from your authenticator app or one of your backup codes (a backup code is used up). Email sign-in codes are not accepted here. Changing the time zone needs neither.
Wrong passwords here count towards the same lockout as wrong sign-ins, and trying too quickly gives "Too many attempts. Please wait a minute and try again."
If your account was created with Google and has no password yet, set one first with Forgot password.
Changes that sign out your other browsers
Changes that affect how your account is protected sign out every other browser where you are signed in. The browser you made the change from stays signed in.
This happens when you change your password, turn the authenticator app or email sign-in codes on or off, remove your recovery email, or confirm a new one. After a password change your API key is also revoked, so generate a new one for your scripts.
Security changes such as a new password, a new or removed email, and two-factor changes also send a notice to your recovery email, so you hear about a change you did not make. If you get one you do not recognize, reset your password right away and contact support@eyalsec.com.