Secure your account

Manage your recovery email, passkeys, password and signed-in devices from Profile menu → Account security.

Applies to Web · Mac · iPhone app · passkeys can only be added in a browser

Account security brings together everything you need to protect your account and get back into it. There is no separate “Settings” menu — you open it from the profile menu in the top bar. The first thing to do is add and verify a recovery email. Without one, there is no way to recover your account if you forget your password.

Open Account security

  1. Click your name at the right end of the top bar (on a phone, your avatar).
  2. Click Account security. If your recovery email isn’t verified yet, it carries a Needs attention badge.

From top to bottom the screen shows Recovery email · Passkeys · Change password · Signed-in devices · API tokens · Blocked users · Recent activity · Storage · Notification emails · Delete account.

Add a recovery email

  1. Enter an address under Recovery email.
  2. Enter your Current password and click Save and send verification. A password is always required to add or change the address, so nobody can swap it while you’re away from your desk and take over the account.
  3. Open the link in the email and click Confirm this address. The link is valid for 24 hours. If the email doesn’t arrive, click Resend email.

The status reads Verified, Awaiting verification or Not set. Password reset and username reminder emails only go to a verified address. Until it’s verified, a warning strip appears at the top of every screen, and Set it up now takes you straight here.

Sign in without a password using passkeys

With a passkey you sign in with Touch ID, Face ID or Windows Hello. Passkeys don’t work on fake sites, so they resist phishing.

  1. On the device you want to use, sign in to CommonNote in a browser (a current version of Chrome, Safari or Edge) and open Account security.
  2. Under Passkeys, enter your Current password, click Add a passkey on this device and follow the device’s prompts.
  3. Next time, click Sign in with a passkey on the sign-in screen in a browser (the Mac and iPhone apps don’t show this button).
  • Where a passkey is stored depends on your passkey provider. Some keep it on that device only; others, such as iCloud Keychain or Google Password Manager, may sync it to your other devices. Keep your password and recovery email so you can still get in if you lose access to your passkey.
  • On a computer without fingerprint or face recognition, clicking the button lets you create the passkey on your phone by scanning a QR code.
  • New passkeys can’t be created inside the Mac app or iPhone app. There you can only review and remove passkeys you already registered.
  • Remove a passkey you no longer use with Remove this passkey (the trash icon).

Change your password

  1. Under Change password, enter your Current password and a New password (10+ characters).
  2. Click Change password.
Changing your password signs out every device except the one you’re using and revokes all your API tokens. If you’ve put a token in a script or AI tool, create a new one and swap it in. A notice is sent to your verified recovery email.

A new password must be at least 10 characters. There are no rules about capitals or symbols, but commonly leaked passwords, passwords built from your username or the service name, and your current password are rejected.

Review signed-in devices and recent activity

  • Signed-in devices lists each device with when it was last used; the one you’re on is marked This device. Cut off a device you don’t recognize with Sign out this device, or use Sign out all other devices.
  • Recent activity records sign-ins, failed sign-ins, password changes, passkeys added or removed, devices signed out and similar events, with device details.
  • Long lists show the first five entries; click Show all to see the rest.
  • A sign-in lasts up to 30 days, and a device that goes unused for 14 days is signed out automatically.

If you see a sign-in you didn’t make, sign that device out and change your password right away. When you sign in on a new device, a notice goes to your verified recovery email. These security emails keep coming even if you turn off Notification emails.

Sign-in attempt limits

You can get your password wrong five times without penalty. After that, each failure makes you wait before trying again: 10 seconds, then 30 seconds, 2 minutes, 5 minutes, 15 minutes and 1 hour. The count resets after 24 hours without a failure. Places in Account security that ask for your password again (recovery email, adding a passkey, creating a token and so on) follow the same rule.

Other sections

SectionWhat it doesMore
API tokensKeys that let scripts and AI tools read and write notes through /api/v1Get started with the Markdown API
Blocked usersPeople you’ve blocked, with UnblockReport and block
StorageAttachment usage and Manage attachment storagePlans and storage
Notification emailsTurns emails about unanswered handoffs on or offGet notifications
Delete accountDeletes your account permanentlyDelete your account