Manage your account identity and enable time-based one-time-password two-factor authentication from the Profile tab.
Where: Account settings → Profile
Before you start
- Use a signed-in account.
- Have an authenticator app available before enabling 2FA.
Key ideas
- Identity details: Update the display name and avatar associated with the signed-in account; the email identifies the authentication account.
- Provider-aware password: Password controls appear for email/password accounts. Google or other provider-backed accounts manage their primary credential with that provider.
- Authenticator-app 2FA: Enabling 2FA creates a TOTP secret and QR setup flow, then requires a verification code before enrollment is completed.
Steps
- Open Account settings and select Profile.
- Update your name or avatar and wait for the successful saved state.
- For an email/password account, enter the current password and the confirmed new password to change it.
- To enable 2FA, start the setup, scan the QR code in a trusted authenticator app, and enter a current code to verify enrollment.
- Sign out and back in when the app reports that the authentication session is too old for a security-sensitive change.
Limitations and important notes
- Password change is shown only for accounts that use an email/password provider.
- Security-sensitive Firebase actions can require a recent login.
- Store recovery information outside flowmo; do not place authenticator secrets in Brain or project content.
Troubleshooting
Profile says the session expired
Log out, sign in again, and retry the password or 2FA action immediately.
The verification code is rejected
Confirm the authenticator entry was scanned from the current setup, use the newest code, and check that the device clock is automatic.