BetaMaShop is in public beta. We improve it continuously, and your feedback shapes what comes next.

Securing your account

Account & creditsEnglish· 3 min read· Updated September 01, 2026

Password, open sessions and two factor codes, plus the one confirmation message in MaShop that overstates what it does.

Account

The Security tab holds three things: your password, your open sessions, and two factor authentication.

It appears only on accounts created with an email and a password. If you signed up through Google or GitHub, the tab is not in the list. Your password, your sessions and your two factor settings then live with that provider instead, and your email address is read only.

Changing your password

MaShop checks the current password by attempting a sign in with it before changing anything. A wrong one is rejected on the spot. The new password must be at least 8 characters.

Reviewing open sessions

The session list is real. It is read from the database, and each row shows the device, the IP address and the last activity. Anything you do not recognise there is worth acting on.

Several sign ins from the same browser collapse into one row, marked with a small counter. Revoking that row closes all of them at once.

Revoke this session closes one connection. The button is disabled on the session you are currently using and points you to the sign out control instead.

That control is worth reading closely. Its confirmation says you will be signed out of all your devices, including this one. That is not what happens: every other session is closed, and the one you are using stays open. The success message then admits it. If you suspect a device is compromised, do not run this from that device. Sign in from a device you trust, run it from there, and change your password.

Two factor authentication

MaShop uses time based codes, the six digit kind produced by an authenticator app. Any standard app works, including Google Authenticator, Authy, 1Password, Microsoft Authenticator and Bitwarden. One method at a time, no SMS.

Press Activate, scan the QR code with your app, then type the six digit code it shows. That is the whole setup.

You can disable it later from the same place. MaShop states plainly what that means before it does it: your account is then protected by your password alone.

Backup codes

Ten single use recovery codes are generated automatically right after your two factor setup is verified. They appear once, in a window with a Copy all button.

Save them somewhere that is not the phone holding your authenticator app. A password manager or a printed sheet both work.

Changing your email address

The email field is on the Profile tab, not on Security. Editing it and saving sends a confirmation to the new address. Nothing changes until you click the link in that message. Your sign in address stays the old one in the meantime, so do not sign out before confirming.

Who else can reach your work

The Team tab is scoped to the project you have open, not to your whole account, even though the window is titled account settings. Inviting someone there gives access to that one project. Three roles exist: owner, editor and viewer. Only the owner sees the invite button, and removing a member cuts their access immediately.

Connectors follow the same rule. Only the project owner can connect or remove one, and removing an access stops every automation that depends on it, across all threads. MaShop names those automations before you confirm.

securityaccount2fasessions
Was this page helpful?
Your feedback is anonymous.