Where to find it
Go to Profile → Security. This tab covers account-level security: two-factor authentication, password changes, login activity, and account deletion — separate from Personal Connections, which manages your tokens for external integrations.Two-factor authentication (MFA)
Pwnbook supports TOTP-based two-factor authentication using any standard authenticator app (1Password, Authy, Google Authenticator, etc.). To enable MFA:- Click Enable Two-Factor Authentication.
- Scan the QR code with your authenticator app.
- Enter the 6-digit code it generates to confirm enrollment.
Exactly how MFA challenges work depends on how your organization authenticates (local password, magic link, or SSO) — the enrollment step above is the same regardless.
Password
If your account uses password-based sign-in, you can set a new password from the Password & Authentication card. This doesn’t apply if you sign in via magic link or SSO only.Login activity
The Login Activity card lists recent sign-ins to your account:
If you spot a session you don’t recognize, click the sign-out icon next to it to revoke that session immediately — the device will be signed out on its next request. You can’t revoke your current session from this list; use Sign Out from the profile menu instead.
Login activity is only available when your organization authenticates via WorkOS (the default for Pwnbook Cloud). Self-hosted deployments using local email/password auth won’t see this card populated.