Skip to content

Profiles and account security

Profile

Under Settings > Profile, set a display name, homepage, identity color, custom status, avatar, and Jitsi call name when the corresponding server features are enabled. Relay synchronizes supported profile values using draft/metadata-2; current master prefers draft/metadata-3 where available. Without a compatible metadata capability, the values remain local to Relay. See User metadata.

Password and two-step sign-in

Open Settings > Security & sessions. If asked to authenticate again, sign out and perform a fresh sign-in before changing authentication methods. A remembered session alone may not authorize enrollment.

Enroll an authenticator

  1. Under Authenticator app, enter Current password and choose Set up authenticator. Forced enrollment after password sign-in does not ask for the password again.
  2. Scan the QR code with a TOTP app, or enter the setup key manually.
  3. Enter Six-digit authenticator code and select Verify and enable. Setup/challenge requests expire after five minutes; start again if needed.
  4. Save the eight one-time recovery codes somewhere separate from Relay, then select I saved my recovery codes. They are shown only once.

Enrolling TOTP adds a second step to fresh local password logins even when the instance does not require MFA for everyone. To remove it, supply the current password and an Authenticator or recovery code, then choose Remove authenticator. If instance policy requires a factor, register a security key before removing the required authenticator; Relay refuses removal of the last required authenticator.

Register a passkey or security key

Under Register a new security key, enter a Key name, choose Register security key, and complete the browser/device prompt. Use HTTPS (localhost is allowed for development) and the same Relay hostname when signing in later. Keep another available factor or recovery method before removing a key.

Passkeys can provide passwordless authentication when two-step sign-in is optional, or act as the second step after a password. Registering a key alone does not opt an otherwise optional account into mandatory password-plus-key login; enrolling TOTP does opt local password logins into a second step. OIDC logins follow the identity provider's MFA policy rather than Relay's local challenge.

Sessions

Review signed-in sessions and revoke any you do not recognize. Remembered sessions can reconnect without repeating MFA when their recorded authentication meets current policy. Enabling required MFA means existing password-only sessions must sign in again on reconnect. Signing out of one browser does not automatically revoke other active sessions.

If you lose your authenticator, use a saved recovery code at the code challenge; each works once. For a lost password or all factors, contact the administrator and follow account recovery. A password reset alone does not remove MFA.

Optional TOTP, recovery codes and the required-local-MFA policy described here are included in Relay 0.11.1.