Security
Sign-in methods, two-factor, sessions, and recovering access when you are locked out.
Reverie accepts eight ways of signing in, and Settings → Security holds five blocks: your password, connected accounts, passkeys, two-factor authentication and active sessions.
Ways to sign in
| Method | How it works |
|---|---|
| Email + password | Password must be at least 8 characters. A new email account has to verify its address before it is usable. |
| The usual OAuth flow. | |
| Google One Tap | The Google account chooser that appears by itself on the login page. |
| Discord | The usual OAuth flow. A connected Discord account is also what the community boost on the lucky draw checks. |
| Magic link | Enter your address and Reverie mails you a one-time sign-in link — no password. |
| Passkey | Face, fingerprint or device PIN instead of a password. |
| Sign in with QR code | Show a QR code on your computer and scan it with a phone that's already signed in. |
| Telegram Mini App | Opening Reverie inside Telegram signs you in from Telegram itself. |
Signing in by QR code
On the login page, choose Sign in with QR code. Scan the code with the scanner in your phone's user menu, or with any camera app. Both screens then show a short verification code.
Check that the two codes match before you approve. Approving a code you did not generate signs somebody else's browser into your account. The challenge expires after 3 minutes; if it lapses, start again.
Your password
Changing a password asks for the current one first. If you created the account with Google or Discord you have no password, so the block reads Set password instead and sends you through the password-reset email to set one.
You need a password for two-factor authentication — the block below only appears for accounts that have one.
Two-factor authentication
Adds a six-digit code from an authenticator app on top of your password.
Open Settings → Security
Choose Enable two-factor authentication.
Confirm your password
The dialog verifies it's really you before it will show a secret.
Scan the QR code
Use any authenticator app, or copy the secret and type it in manually.
Enter the six-digit code
That verifies the setup, and two-factor is on.
There are no backup codes. Reverie never shows you a set of recovery codes, and there is nothing to save. If you lose the authenticator app or the phone it lives on, you cannot get past the code screen yourself — you have to contact support to get two-factor removed. Before you enable it, make sure your authenticator is backed up or set up on more than one device.
Turning it off is one click in the same block.
Passkeys
Add passkey registers the device you are on. The list shows each passkey's name, when it was created, and whether it is a Synced passkey (shared through your password manager or platform account) or a Single-device passkey (bound to that one device). Passkeys can be deleted from here.
Connected accounts
Google and Discord show as either Connect or a check mark.
Connecting is one-way. There is no disconnect control — once a social account is linked, it stays linked. Only link accounts you own and expect to keep.
Active sessions
Every signed-in browser is listed with its IP address and the raw browser identification string it sent. The X ends that session.
Sessions last 30 days. A session's cookie is cached for up to an hour, so one you revoke can keep working for that long afterwards — if you are ending a session because someone else has it, change your password as well.
If you are locked out
| Situation | What to do |
|---|---|
| Forgot your password | Forgot password on the login page mails you a reset link. |
| No password, can't use Google or Discord | Use a magic link to the same address, then set a password from Settings → Security. |
| Lost your authenticator | Contact support. There are no backup codes. |
| Signed in on your phone but not your laptop | Use Sign in with QR code on the laptop. |
| Sign-in shows Account Suspended | The screen gives the reason and, for a temporary restriction, the date it ends, plus the support address to appeal to. A moderation decision on a character or other content is appealed in-app instead — see Reports & appeals. |
Related
- Getting help — the support channels and how fast each replies
- Your profile — the fields the settings pages let you change
- Data & privacy — what is stored, and how to close the account
- Reports & appeals — contesting a moderation decision
- API keys — credentials for the device API, managed separately