Secure your account
Turn on two-factor authentication, add a passkey, and manage active sessions.
Blake stores your CRM, your drafts, and your team's activity. Securing your account with two-factor authentication and a passkey takes five minutes and stops the most common attack vectors.
Where the security settings live
Open Settings > Account. Scroll to the Security card. Every option in this article lives on that card.
Change your password
Click Change password. Blake asks for your current password and a new one. The strength meter and checklist show minimums:
- At least 8 characters.
- At least one lowercase letter.
- At least one uppercase letter.
- At least one number.
Weak passwords are rejected inline. On success, Blake keeps your current session active and asks whether to revoke your other sessions.
Turn on two-factor authentication
Two-factor authentication (2FA) requires a code from an authenticator app on top of your password. Blake supports TOTP, the standard used by Google Authenticator, 1Password, Authy, and similar apps.
- Click Set up 2FA. Blake opens the setup wizard.
- Scan the QR code with your authenticator app, or copy the manual secret and paste it into the app.
- Type your account password to confirm you are you.
- Enter the six-digit code from the app.
- Blake shows ten backup codes. Copy or download them as
blake-backup-codes.txtand store them somewhere safe. Each code works once, in case you lose your device.
Once 2FA is on, Blake asks for a code on every new device login and after 24 hours on a trusted device.
Turn 2FA off
Click Disable 2FA. Blake asks for your password and one authenticator code before turning it off. This is a security-sensitive action; Blake requires a fresh check even if you are already signed in.
Add a passkey
Passkeys are a phishing-resistant sign-in method that live on your device (Face ID on iPhone, Touch ID on Mac, Windows Hello, hardware keys).
- Click Add passkey. Blake starts the WebAuthn flow.
- Follow your device's prompt (Face ID, Touch ID, or hardware key touch).
- Blake registers the passkey and adds it to your passkey list.
Blake supports multiple passkeys per account so you can add one per device you use.
Passkeys are additive to your password and 2FA, not a replacement. Even with a passkey, keep your backup codes safe in case a device is lost.
Delete a passkey
Click the trash icon next to a passkey. Blake asks for confirmation before removing it. Blake never asks for your account password to remove a passkey; the confirmation is enough.
Single Sign-On (SSO)
Single Sign-On (SSO) is available on Enterprise only.
Enterprise workspaces can sign in through their own identity provider (Okta, Microsoft Entra ID, Google Workspace, or any SAML 2.0 IdP). Contact your Blake account team to configure SSO for your workspace.
Active sessions
The Active sessions section lists every device that is currently signed in to your Blake account. Each row shows the device label (Web, Desktop App, Mobile), the location as reported by the browser, and how long ago it was last active.
- Revoke on a row signs that device out immediately.
- The row for the device you are currently on is labelled This session and is not revocable from itself.
- Sessions expire after 7 days of inactivity or 24 hours of continuous use.
What Blake logs about sign-ins
Blake emails you when:
- A new device signs in.
- Your account is locked for too many failed attempts.
- Someone changes your password.
- Someone turns 2FA on or off.
Emails come from notifications@useblake.ai.
If you cannot sign in
- Lost your authenticator app: use a backup code on the sign-in screen. Each code works once.
- Lost both your device and backup codes: contact your workspace Admin. They can request an account reset via
support@useblake.ai. - Password stopped working after a change: use the Forgot password link on the sign-in screen to reset via email.