ColituHelp Centre
Security & privacy

Account security

See and close your sessions, what the security e-mails mean, what happens when you change your password, and the 24-hour lock after a reset.

Your first stop for account security is colitu.com/account/security (Account → Security). There you manage your password, two-step verification and passkeys, and see your open sessions.

Your sessions

The Browser sessions section lists every browser signed in to your account on the website. Each row shows:

  • a device label (browser · operating system),
  • the country,
  • the sign-in method (password, passkey and so on),
  • the IP address and the last activity.

If you see a session you do not recognise:

  • Close

    ends only that session.

  • Close other sessions

    ends every session except the one you are using now. Your current session stays open.

  • Sign out everywhere

    signs you out everywhere, this browser included.

Devices with the apps are not in this list; they are on Account → Devices, see Device management.

What happens when you change your password

When you change your password on the website:

  • the browser session you are in stays open;
  • all other web sessions and the refresh tokens of all apps are ended;
  • app access tokens issued before the change stop working immediately. If an app shows the error AUTH_SESSION_REVOKED, sign in again with your new password (see Error codes).

If you are resetting the password with an e-mail code, see Password reset.

The 24-hour lock after a reset

For 24 hours after you reset your password with an e-mail code, two things cannot be done:

  • deleting the account,
  • turning off two-step verification.

If you try, you see the error RECOVERY_LOCKED. The lock stops someone who has taken over your mailbox from resetting the password and immediately deleting the account or switching off verification. After 24 hours these actions open again.

Limit on password checks

Actions that ask for your password again (changing the password, deleting the account, two-step verification changes, adding and deleting passkeys) are limited to 10 attempts per 15 minutes per account. If you hit the limit, wait a while and try again.

Security e-mails

We send a security e-mail to your account's address in these cases:

EventNote
A new app deviceNot sent for the first device on the account
A sign-in from a new countryWhen no sign-in from that country was seen in the last 90 days
Two-step verification turned on or off
Recovery codes regenerated
A passkey added or removed
A password change

If one of these e-mails reports something you did not do, change your password right away, click Sign out everywhere and write to support. Colitu staff and Colitu Bot never ask you for a password or a verification code.

Was this article helpful?

Still need help?

Colitu Bot answers in seconds, and our support team helps in three languages.