All security settings live in one place: Settings → Profile, under the Security section. From there you can change your password, manage MFA, add or remove passkeys, and review and revoke active sessions.
Change your password
- Go to Settings → Profile.
- In the Security section, find the Password row and select Change password.
- In the modal, enter your Current password.
- Enter a New password — at least 12 characters.
- Re-enter it in Confirm new password.
- Select Update password.
After a successful change you are signed out and must sign back in with the new password.
Enable MFA (authenticator app)
- Go to Settings → Profile → Security.
- In the Multi-factor authentication row, select Enable MFA.
- Scan the QR code with an authenticator app (Google Authenticator, Authy, Microsoft Authenticator, or 1Password). If you can't scan, use the manual text key shown below the QR code.
- Enter the 6-digit code from your app and select Verify and enable.
- When your backup codes appear, copy or save them somewhere safe — these are shown only once. Select I have saved my codes to finish.
Multi-factor authentication now shows Enabled in the Security section.
Disable MFA
You can disable MFA if your account is not required to have it. Staff and owner accounts are required to keep MFA enabled — the Disable button will not appear for those accounts.
- In the Multi-factor authentication row, select Disable.
- Enter a valid 6-digit code from your authenticator app to confirm.
- Select Disable MFA.
Your recovery codes are invalidated when MFA is disabled.
Add a passkey
A passkey lets you sign in with Touch ID, Face ID, Windows Hello, or a hardware security key. A registered passkey also satisfies the MFA requirement for staff and owner accounts.
- Go to Settings → Profile → Security.
- In the Passkeys row, select Add passkey (or Manage if you already have one).
- In the modal, select Register new passkey.
- Follow your device's prompt to complete registration.
Your new passkey appears in the list, labelled as either a security key or a synced passkey, with the date it was added.
Remove a passkey
- In the Passkeys row, select Manage.
- Find the passkey you want to remove and select Revoke.
Removing all passkeys means you must use email and password (and MFA code, if enrolled) to sign in.
Review and revoke active sessions
Active sessions are shown in the Active Sessions section at the bottom of Settings → Profile. Each entry shows the device type, browser, operating system, and when it was last active. Your current session is marked This device.
To revoke a specific session on another device, select Revoke next to it. To sign out all other devices at once, select Revoke all other sessions.
Revoking a session signs that device out immediately.
Notes
- Passkeys are stored on your device and, if your platform supports it, backed up and synced through your passkey manager.
- If you've lost access to your MFA device and can no longer sign in, contact your gym owner or support — see I lost access to my MFA authenticator or I want to revoke a session.