Support

Account and Security

Manage passwords, two-step verification, linked Google sign-in, sessions, trusted devices, and security alerts.

Passwords

Users can change their password from account settings when signed in. If they cannot sign in, they can use the password reset flow where available.

  • Choose a password that is difficult to guess.
  • Do not share passwords with other users.
  • If a password may be exposed, change it immediately.

Two-step verification

Two-step verification adds one check after a successful password sign-in. Email codes and approval from another signed-in device can be enabled separately or used together.

  • Email verification requires a verified contact email.
  • Device verification requires at least one trusted browser or device.
  • If both options are enabled, choose either one when signing in.
  • Google sign-in does not show an additional EduVerse verification step because Google has already authenticated the linked account.
  • An organization admin with device-only verification can use the verified organization contact email as a recovery option without enabling email codes for everyday sign-ins.

Avoid getting locked out

Before enabling a method, make sure you can keep access to its email inbox or at least one other signed-in trusted device. Keep both methods available when possible.

Sign in with an email code

  1. 1Choose Send a code by email.
  2. 2Open the inbox shown on the verification screen.
  3. 3Enter the six-digit code within 10 minutes.
  4. 4Choose Verify and sign in. The successful browser becomes trusted.

No code?

Check the masked address on screen and the inbox spam folder. You can request another code after the resend wait period.

Approve from another signed-in device

You can approve from any phone, tablet, or computer where you are already signed in to the same EduVerse account and that browser or device is trusted.

  1. 1Open EduVerse on another device where this account is already signed in.
  2. 2Open the sign-in approval notification and choose Approve sign-in.
  3. 3If the notification is not visible, open your profile or Settings, go to Security, then Devices & sessions, and approve the waiting sign-in.
  4. 4Return to the new device. Its sign-in screen continues automatically.

Only approve your own attempt

Do not approve a request you do not recognize. Review your sessions and change your password if an unexpected request appears.

Contact email

Open Settings > Security > Verification & recovery to manage recovery email and two-step verification. Security uses the same hover or chevron sub-tab menu as Finance: Sign-in methods contains password and Google sign-in; Devices & sessions contains browser access, active sessions, and local chat recovery. The verified contact email is used for email sign-in codes and other security communication. It can differ from the email used as the account name.

  • Organization admins use the verified organization contact email shown in Settings > Profile.
  • Other users can add and verify a personal contact email from Settings > Security.
  • A user with a linked Google account can choose its verified Google email as the contact email.
  1. 1Choose Change contact email beside the current address. EduVerse sends a six-digit code to that address.
  2. 2Enter that code to unlock the email field. The field stays unlocked only in this signed-in session and for up to 15 minutes.
  3. 3Enter and save the new address.
  4. 4Open the new inbox and enter the new verification code. Until this is done, the new address cannot receive email sign-in codes.

Why two codes are needed

The first code proves that the person changing the address still controls the current email. The second code proves that the replacement address works. If you sign out before saving the change, request a new code from the current address after signing in again.

Using your linked Google email

If choosing the linked Google email would replace an existing verified contact email, EduVerse still sends a confirmation code to the current address first. The Google address is already verified by Google, so it is ready after the change is confirmed.

Getting help when you cannot complete two-step verification

If you cannot use your email code or any trusted device, an organization administrator may be able to remove the extra sign-in check for your account. This does not reveal your password or sign the administrator into your account.

Who needs helpWho can helpWhat they can do
Teacher, manager, finance manager, student, or guardianOrg admin or sub-adminCopy a password-reset link or turn off two-step verification when the user is locked out.
Sub-adminOrg admin onlyCopy a password-reset link or turn off two-step verification when the sub-admin is locked out.
Org admin who can open the organization contact inboxNo staff action is neededChoose the organization recovery email on the sign-in screen.
Org admin who also lost the organization contact inboxPlatform supportAfter confirming the request, replace the verified organization contact email.

What a two-step verification reset does

Turning off two-step verification removes the extra check at sign-in. It does not change the password, sign out other sessions, or remove trusted devices. After signing in, the user should review Security and turn protection back on with options they can access.

Organization admin email recovery

An org admin who normally approves sign-ins from another device can use the verified organization contact email if those devices are unavailable. The sign-in screen labels this as the organization recovery email.

  1. 1On the sign-in check, choose Use organization recovery email.
  2. 2Open the organization contact inbox and enter the six-digit code.
  3. 3Complete sign-in. The email remains a recovery choice; email codes are not automatically turned on for every future sign-in.

Lost access to the recovery email too?

Contact platform support. After confirming the request, a platform admin can replace the organization contact email. Start sign-in again after it is changed so the code is sent to the new address.

Linked Google sign-in

Linking Google adds another sign-in method. The linked Google email is shown in Security, can be unlinked there, and can be adopted as the contact email when the user chooses it.

Sessions and devices

A session means the account is signed in. Browser trust means that browser can approve sign-ins and use protected Chat and Mail. These controls are separate.

  • Sign out ends the selected session but does not automatically remove browser trust.
  • Remove trust stops that browser from approving sign-ins or opening new protected content but may leave its session signed in.
  • Sign out all other sessions keeps only the session currently in use.

Approve a browser for secure messaging

Signing in and trusting a browser are separate steps. New browsers need approval for secure Chat and Mail by default, including the first browser. Approve from an existing trusted browser or request a six-digit code at your verified recovery email. Organization admins use the organization contact email; other accounts use their own verified contact email.

  • Request the code in the browser trust prompt and enter it in that same signed-in browser. The code expires after 10 minutes; wait one minute before requesting another. Five incorrect attempts invalidate the challenge.
  • Browser approval codes cannot be used as sign-in or contact-email-change codes. Signing out, changing the recovery email, replacing the browser keys, or removing trust can invalidate an outstanding approval.
  • Approval enables future messages. An existing trusted browser must share available recent Chat history; email approval cannot recover old private keys or messages when every copy of the keys has been lost.
  • If no trusted browser or verified recovery email is available, Security offers a password-confirmed secure messaging reset. Read its confirmation carefully: old encrypted history cannot be recovered through this reset.

Automatically trust new browsers

Automatic browser trust is off by default. You can enable it from an already trusted browser in Security. When enabled, a new browser matching an active signed-in session can be trusted without a separate messaging approval. The sign-in two-step verification check still applies.

Existing access and history

Turning this setting off affects future registrations; it does not remove trust from existing browsers. Previously revoked browsers still need explicit approval. Automatic trust does not restore old encrypted history.

Login security alerts

Login email alerts and login push alerts can be switched on or off independently. They cover new-device and new-location sign-in activity. Security emails and approval notifications include the request time in UTC, browser, operating system, device when available, approximate country, and IP address. Missing information is shown as Unknown. Country is estimated from the network address and may reflect a VPN; it is not proof of identity.

Recommended

Keep at least one login alert channel enabled so unexpected account activity is easier to notice.