Email, password, and phone live in User Settings → Security & Login → Account.
The address is masked by default: Reveal / Hide.
Change email:
- Click Change Email.
- If the current address is verified, confirm a one-time code from the old inbox, then enter the new address and confirm that code too.
- If the address is still unverified, you only need the new address and its code.
An unverified inbox shows Email verification required and Resend Email. Email-change and claim codes can be resent every 30 seconds.
Password
- Use Change Password. In this modal the new password is 8–128 characters (the API allows up to 256).
- Under the button you will see Last changed: … or Never.
- If you are on the login screen, use Forgot your password.
Sensitive actions may ask you to verify your identity with a password, code, or passkey. That token lasts a few minutes.
Phone
The phone section appears only after authenticator (TOTP) 2FA is enabled.
- Add Phone — country, number, then a 6-digit SMS code.
- Remove also turns off SMS 2FA.
- SMS 2FA is a backup to the authenticator app. Partners and some staff roles cannot use SMS backup.
For the full 2FA setup see Two-factor authentication and passkeys.