Secure your Hushdesk account
A five-minute checklist to protect your account and your customers' data, using a strong password, two-step sign-in, a passkey and a review of your devices.
Last updated 2 min read
Your Hushdesk account can read customer conversations and, for admins, change settings for your whole team. These five steps take about five minutes and protect both.
Before you start
- Who can do this: everyone, for their own account.
- Plan: all plans.
- What you need: a confirmed email address, your phone, and about five minutes.
Step by step
- Confirm your email. Two-step sign-in and passkeys need it. See Confirm your email address.
- Use a strong password. Under Password, choose at least 10 characters. See Change or set your password.
- Turn on two-step sign-in. Under Two-step sign-in, press Turn on and scan the code. See Set up two-step sign-in.
- Save your recovery codes somewhere other than your phone. See Use and renew your recovery codes.
- Add a passkey under Passkeys for quick, phishing-proof sign-in. See Add a passkey for quick, safe sign-in.
- Review your devices under Signed-in devices and sign out any you do not recognise. See See and sign out signed-in devices.
What happens next
Every one of these changes is written to the audit log of each workspace you belong to, so owners can see that your security changed. Changing your password or email signs out every other device. From now on, signing in with a password or email link also asks for your authenticator code; signing in with a passkey does not.
Tips
- Owners and admins should do all five steps. Their accounts can change settings for everyone.
- Never share one login between teammates. Seats are unlimited on every plan, so invite each person instead.
- Use a password manager. It can also store your recovery codes.
- On a shared computer, use Sign out when you finish.
Troubleshooting
"Confirm your email first (we sent you a code), then add this."
Two-step sign-in and passkeys need a confirmed email. Use the 6-digit code from your welcome email, or send a new one.
"For your security, sign out and sign in again (in the last 15 minutes) to do this."
This change needs a fresh sign-in. Sign out, sign in again and try within 15 minutes.
"That password is too common. Try a short phrase instead"
Pick something less predictable, such as three unrelated words.
"Don’t use your email address in your password"
Remove your email address, or the part before the @, from the password.
Frequently asked questions
What is the most secure way to sign in to Hushdesk?
A passkey. It uses your phone's or computer's fingerprint, face or PIN, cannot be phished and skips the code step. Add one under Security and sign-in. Keep a password with two-step sign-in as a backup way in, so a lost device never locks you out.
Why does Hushdesk ask me to sign in again before some changes?
Adding a passkey, and setting a password or changing your email when you have no password yet, need a sign-in in the last 15 minutes. This stops someone who finds an open browser from adding their own way into your account. Sign out, sign in again, then repeat the change.
What makes a good Hushdesk password?
At least 10 characters, and a short phrase works well. Hushdesk refuses very common passwords, passwords made of one repeated character and passwords that contain your email address. Use a password manager so every service gets its own password, and never reuse the one from your email account.
How do I know if someone else used my account?
Open Signed-in devices in your account. It lists every browser that is signed in, with the device and the last time it was used. If you see one you do not recognise, sign it out, change your password and turn on two-step sign-in. Admins can also check the audit log.
Does a password change sign out my other devices?
Yes. Changing your password ends every other signed-in session straight away, and so does changing your sign-in email. The browser you used to make the change stays signed in. Other devices sign in again with the new password or email.
Was this helpful?
Related articles
- Set up two-step sign-inProtect your account with a code from an authenticator app such as Google Authenticator, 1Password or Authy, plus ten one-time recovery codes.
- Add a passkey for quick, safe sign-inSign in with Face ID, Touch ID, Windows Hello or a security key instead of typing a password. Add, rename and remove passkeys from your account.
- See and sign out signed-in devicesCheck every device and browser signed in to your account, with where and how it signed in, and sign out any you do not recognise, or all others at once.
- Change or set your passwordChange your Hushdesk password, or set one if you sign in with email links or passkeys. Changing it signs out every other device for your safety.
Still stuck?
Chat with the Hushdesk team. A person answers on every plan.