Skip to main content

Securing Your Account: 2FA & Password Changes

Because your Circus account controls real configuration and real spend, it's worth locking down. The Account Security area is where you enable two-factor authentication and change your password.

Two-factor authentication

2FA is recommended but off by default — you opt in. It uses a standard time-based authenticator app (the same kind you'd use for other services), so enabling it is a short, multi-step flow:

  1. The app shows a QR code — scan it with your authenticator app.
  2. It shows a set of backup codes — save these somewhere safe; they're your way back in if you lose the authenticator.
  3. You confirm setup by entering a current code from the app.

An invalid code at any step just shows an error and lets you retry. Once 2FA is on, every future sign-in asks for an authenticator code after your password, and the security page now offers a disable option — turning 2FA off requires a valid authentication code, so a stray logged-in session can't quietly remove it.

Changing your password

A password change asks for your current password, the new password, and a confirmation. If you have 2FA enabled, it also requires a current authenticator code — so a change always proves both something you know and something you have.

Passwords don't expire in Circus, so you change yours when you choose to rather than on a forced schedule.