Account and security
Account settings manage sign-in identities, passwords, and active sessions. Account credentials and Lumoswitch access keys serve different purposes and must not be interchanged.
Sign-in methods
Depending on the site configuration, Lumoswitch can offer password, email-code, and SMS-code sign-in. Some sites require a verified phone number before console access. Verification codes have expiry, frequency, and attempt limits.
Passwords
Open Settings, complete the required identity check, and choose a new password. Do not reuse an upstream-provider password or place it in source control, tickets, or chat.
After a suspected compromise, change the password and review both login sessions and API access keys.
Sessions
Settings lists recent session creation, expiry, and status. Revoke an unfamiliar session individually, or revoke all sessions to require sign-in again on other devices.
Revoking a login session does not disable Lumoswitch access keys. Handle exposed API credentials from Access keys separately.
Username and identities
The username is a console display identity and may have a change cooldown. Email addresses and phone numbers are sign-in identities and require the corresponding verification flow when added or changed.
Respond to suspicious activity
- Change the account password and revoke all sessions.
- Disable suspicious Lumoswitch access keys.
- Rotate any upstream provider key that may be exposed.
- Review API configurations, projects, and upstream changes.