> ## Documentation Index
> Fetch the complete documentation index at: https://docs.causfy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> Passkeys, two-factor authentication and why you are asked again on sensitive operations.

Your account controls public causes and, if you fundraise, money. It deserves more than a password.

It is all in **Configuration › Account Settings**.

## Passkey

A passkey replaces the password with your fingerprint, your face or the device PIN. There is nothing to remember and nothing to steal: the key never leaves your phone or your computer.

It is the most secure method and the most convenient one at the same time, which almost never happens.

<Steps>
  <Step title="Open passkeys in Configuration">
    You will see the ones you already have registered.
  </Step>

  <Step title="Add one">
    The device asks you for your fingerprint, your face or the PIN. That's all.
  </Step>

  <Step title="Add the one for your other device">
    You can have several. It is a good idea: if you lose your phone, you can still get in from the computer.
  </Step>
</Steps>

<Tip>
  Register at least two, on two different devices. A single passkey on a single phone is a single point of failure.
</Tip>

## Two-factor authentication

A code that changes every few seconds in an authentication app. When you turn it on you are shown a QR code to scan with that app.

It works on its own and it works as a backup for the passkey.

<Warning>
  Keep the recovery codes you are given when you turn it on, somewhere other than your phone. Without them and without the phone, recovering the account depends on support and takes time.
</Warning>

## Why you are sometimes asked again

There are operations that are not satisfied with the session being open: requesting a cause's bank account, changing the ways you get paid, touching sensitive data. In those cases you are asked to confirm who you are again.

**You are asked for whatever you have turned on**, no more and no less:

| What you have                  | What you are asked for            |
| ------------------------------ | --------------------------------- |
| Nothing                        | Nothing, the operation goes ahead |
| Two-factor authentication only | The code                          |
| Passkey only                   | The passkey                       |
| Both                           | You choose which to use           |

If you cancel, the operation simply doesn't happen. Nothing else follows.

<Info>
  Being asked for nothing means you have no method turned on. That is the sign that you should turn one on.
</Info>

## If you see something odd

Check who has access and where it has been signed in from. [Devices and sign-ins](/en/cuenta/dispositivos)
