Sign in and passwords
Sign in with an email and password, Google, GitHub, or your company account. Set a strong password, reset a forgotten one, and see where you are signed in.
You can sign in to Avaloi with an email and password, with Google or GitHub, or through your company's single sign-on. This article covers passwords. For the other ways, see Connected accounts and Single sign-on with SAML.
Create an account with a password
- On the sign-up page, enter your name, your email, and a password.
- Open the link in the email from Avaloi. The link works for one hour. An address is not an account until you open it.
- Sign in.
If the address already has an account, Avaloi shows the same screen and sends the owner of the address a note instead. The screen never says whether an address has an account.
Password rules
- 12 to 128 characters. Longer is better. A few random words work well.
- Not a common password. Avaloi checks a short list on its own servers and also rejects repeats such as
aaaaaaaaaaaa, runs such as123456789012, and a common word with digits around it. Nothing leaves Avaloi for this check. - Not your name or the first part of your email address.
Avaloi stores only a one-way hash of your password (Argon2id). Nobody at Avaloi can read it.
Wrong passwords and lockouts
Five wrong passwords for one address in 15 minutes lock that address for one minute. Each further wrong password doubles the wait, up to 30 minutes. One IP address that tries many accounts is slowed the same way. The message for a wrong password is the same for an address with no account, so it never reveals which addresses exist. Signing in with the right password after the wait works as normal.
Reset a forgotten password
- On the sign-in page, choose Forgot your password?
- Enter your email. Avaloi shows the same confirmation for every address.
- Open the link in the email. It works once and expires in 30 minutes. A new request cancels the older link.
- Choose a new password. Avaloi signs you out everywhere, forgets your trusted browsers, and emails you a security notice.
If you signed up with Google or GitHub and have no password, the same link creates one.
Change your password
- Open Account settings, then Security.
- Under Password, enter your current password and a new one.
- Save. Avaloi signs out your other sessions and keeps this one.
Create a password after Google or GitHub
If you signed up with Google or GitHub, Avaloi suggests a password so you can still sign in if that provider is not available. You can skip it. The suggestion shows until you create one or choose Skip for now.
See where you are signed in
Account settings, then Security, lists your sessions with the browser and IP address of each. Sign out one session, or choose Sign out everywhere else. The Recent activity list shows sign-ins, failed sign-ins, resets, and security changes. Avaloi also emails you when your password, two-factor, or a sign-in method changes.
Quick answers
Does Avaloi check my password against a breach database? No. It checks a local list of common passwords and a few patterns, and nothing is sent anywhere. Use a password you do not use on another site.
I signed in once and now the page says to check my email. The password was right, but the address is not verified. Avaloi sent a fresh link. It works for one hour.
Why did I get a security email? Something changed on your account, such as a password reset or a new sign-in method. If it was not you, reset your password and turn on two-factor authentication.
Can support reset my password in chat? No. Use Forgot your password?. If you cannot reach the inbox, file a recovery request. Support never completes recovery in chat.
API
POST /v1/auth/sign-inPOST /v1/auth/sign-upPOST /v1/auth/verification/resendPOST /v1/auth/password/forgotPOST /v1/auth/password/resetPOST /v1/users/me/passwordGET /v1/users/me/sessionsDELETE /v1/users/me/sessionsGET /v1/users/me/security/events
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.