Manage password and account security
Last updated: July 23, 2026
Open Settings → Password & Security to manage security for the signed-in account. These settings do not change another teammate's password or two-factor authentication.
Change your password
- Select Change Password.
- Enter the current password.
- Enter a new password containing at least eight characters.
- Enter the new password again under Confirm New Password.
- Select Update Password.
The new password must differ from the current password. Use a unique password that is not shared with another service or teammate.
Changing the password does not automatically sign out existing sessions in the current release. If you changed it because the account or a device may be compromised, contact a account administrator or Support to coordinate any additional access revocation.
An administrator can also reset another eligible teammate's password from Team Members.
Enable authenticator-app 2FA
The Two-Factor Authentication section appears only when an administrator has enabled 2FA for the account.
- Select Enable beside Authenticator App (TOTP).
- If Winly asks you to verify your password, enter the current account password and continue.
- Scan the QR code with an authenticator app.
- If scanning fails, select Trouble scanning? and copy the displayed secret into the authenticator app manually.
- Enter the six-digit code generated by the app.
- Select Verify.
- Save the recovery codes before selecting Done.
The setup is not complete until a valid six-digit code is verified.
Store recovery codes
After initial setup, Winly displays recovery codes with a copy control. Store them in a secure password manager or another location available only to you.
Each recovery code can be used once from the two-factor sign-in prompt. After one is accepted, Winly removes it and reports how many remain. The released settings page does not provide a recovery-code regeneration control.
Disable authenticator-app 2FA
Return to Settings → Password & Security and select Disable beside Authenticator App (TOTP). Winly can ask for the current password before allowing the change.
Disabling the last enabled two-factor method clears the stored recovery codes. Save any records you need before making the change, but do not reuse old recovery codes after re-enabling TOTP.
Recover access
- If the authenticator is unavailable, select Use recovery code instead on the verification prompt and enter one unused recovery code.
- If the current password is forgotten before sign-in, use the password-reset flow from the login page.
- If no authenticator or recovery code is available, contact Support from the business email associated with the account. Never send a password, verification code, QR code, setup secret, or recovery code in the request.