Authentication Options
Password
Traditional email and password authentication.
Passkeys
Modern passwordless authentication using biometrics or security keys.
Password Security
Setting a Strong Password
Your password should be:- At least 8 characters long
- Include uppercase and lowercase letters
- Include numbers
- Include special characters
Changing Your Password
Forgot Password
If you forgot your password:- Go to the sign-in page
- Click Forgot Password
- Enter your email address
- Check your email for reset instructions
- Click the link and set a new password
Password reset links expire after 1 hour for security.
Passkeys
Passkeys offer passwordless authentication using:- Face ID or Touch ID on Apple devices
- Windows Hello on Windows devices
- Fingerprint sensors on Android devices
- Hardware security keys (YubiKey, etc.)
Benefits of Passkeys
Phishing Resistant
Passkeys can’t be phished or stolen like passwords.
Convenient
Sign in with a quick biometric scan.
Cross-Device
Passkeys sync securely across your devices.
No Password to Remember
Eliminate the need for password memorization.
Adding a Passkey
Using Passkeys to Sign In
- Go to the sign-in page
- Click Sign in with Passkey
- Authenticate with your biometric or security key
- You’re signed in immediately
Managing Passkeys
View and manage your passkeys:- Go to Settings → Security
- See list of registered passkeys
- Each passkey shows:
- Device type
- When it was added
- Last used date
Removing a Passkey
To remove a passkey:- Go to Settings → Security
- Find the passkey you want to remove
- Click Remove
- Confirm the removal
Account Recovery
If You Have a Password
Use the Forgot Password flow to reset via email.If You Only Have Passkeys
Passkeys are tied to your devices. If you lose access to all devices:- Try signing in on a device where your passkey synced
- Use your iCloud, Google, or Microsoft account recovery
- Contact support as a last resort
Session Management
Active Sessions
View where your account is signed in:- Go to Settings → Security
- Find Active Sessions
- See list of devices and browsers
- Device type and browser
- Location (approximate)
- Last activity time
Signing Out Other Sessions
To sign out a suspicious or old session:- Find the session in the list
- Click Sign Out next to it
- That session is immediately terminated
Security Best Practices
Use a password manager
Use a password manager
Password managers like 1Password, Bitwarden, or Apple Keychain:
- Generate strong, unique passwords
- Securely store your credentials
- Auto-fill login forms
- Sync across devices
Enable passkeys when possible
Enable passkeys when possible
Passkeys are more secure than passwords because:
- They can’t be guessed or cracked
- They’re resistant to phishing
- They don’t work on fake websites
Review sessions regularly
Review sessions regularly
Periodically check your active sessions:
- Sign out sessions you don’t recognize
- Sign out old devices you no longer use
- Report suspicious activity to support
Keep your email secure
Keep your email secure
Your email is used for password resets:
- Use a strong, unique email password
- Enable two-factor authentication on your email
- Don’t share email access with others
Be careful with shared computers
Be careful with shared computers
Data Security
Encryption
- In transit: All data encrypted with TLS 1.3
- At rest: Database encrypted with AES-256
- Passwords: Hashed with bcrypt (never stored in plain text)
Access Control
- Only you and invited collaborators can see your data
- Chainbook staff cannot access your data without permission
- No data is shared with third parties
Infrastructure
- Hosted on enterprise-grade cloud infrastructure
- Regular security audits and penetration testing
- 24/7 monitoring for suspicious activity
Reporting Security Issues
If you discover a security vulnerability:- Email [email protected]
- Describe the issue in detail
- Include steps to reproduce if possible
- We’ll respond within 24 hours
We appreciate responsible disclosure and may offer rewards for significant findings.
Frequently Asked Questions
Is two-factor authentication (2FA) available?
Is two-factor authentication (2FA) available?
Passkeys provide strong authentication similar to 2FA. Traditional TOTP-based 2FA is on our roadmap.
Can I use both password and passkeys?
Can I use both password and passkeys?
Yes, you can have both enabled. Use whichever is convenient when signing in.
What if I lose my phone with my passkey?
What if I lose my phone with my passkey?
If your passkeys sync via iCloud, Google, or Microsoft, access them from another device. Otherwise, use your password to sign in.
Are my wallet private keys safe?
Are my wallet private keys safe?
Chainbook never asks for or stores private keys. We only track public wallet addresses using publicly available blockchain data.