Skip to main content

Two-step sign-in, passkeys and trusted browsers

How Gaveli protects your account with two-step sign-in, passkeys, and control over where you're signed in.

Written by Jason

Your Gaveli account holds sensitive case data, so every account is protected by two-step sign-in. You can manage all of this from Settings → Profile, under the security cards.

Two-step sign-in

When you sign in from a browser you haven't trusted, we email you a six-digit sign-in code to confirm it's really you. Entering the code lets you trust that browser for 30 days, so everyday sign-ins stay quick.

This protection is built into every account — there's nothing to set up and nothing to turn off. It's shown as Two-Step Sign-In on your Profile page, marked Always on.

🖼️ Image slot — The security cards on the Profile settings page: Two-Step Sign-In, Passkeys, and "Where you're signed in".

Passkeys — the quickest way to sign in

A passkey signs you in with Face ID, Touch ID, Windows Hello, or your device PIN — nothing to type, and no sign-in code to wait for. It stays on your device or in your password manager, and it only ever works on Gaveli. Because a passkey confirms it's you in one step, signing in with one skips the emailed code entirely.

Add a passkey

  1. Go to Settings → Profile and find the Passkeys card.

  2. Choose Add a passkey and give it a name so you can tell your devices apart (for example, "Work laptop").

  3. Your browser will ask you to confirm with Face ID, Touch ID, or your device PIN.

If you've been signed in for a while, adding a passkey needs a fresh sign-in first — log out, log back in, and try again.

Rename or remove a passkey

Each passkey in the list can be renamed or removed. Removing one stops it working for signing in to Gaveli; you can also delete it from your device or password manager separately.

Sign in with a passkey

On the login page, choose Sign in with a passkey and confirm on your device. If a passkey isn't available, you can always fall back to your email and password, and we'll email you a sign-in code.

Passkeys need a recent version of Chrome, Edge, or Safari. If your browser can't store passkeys, you'll see a note on the Passkeys card.

Where you're signed in

The Where you're signed in card lists every browser that currently has access to your account, including the one you're using now. If you spot a browser you don't recognise, choose Sign out next to it, or Sign out everywhere else to end every session except your current one.

A note on security

A sign-in code emailed to you stops someone signing in with a leaked or reused password. A passkey goes further — it can't be phished, which is why it's the safest way to sign in. Adding a passkey to the devices you use most is the single best thing you can do to protect your account.

Did this answer your question?