Profile and Security
Manage your personal information and secure your account. Access these features from the user menu at the bottom of the sidebar.
Profile
Section titled “Profile”Update your personal information and manage your email address.
Update Your Name
Section titled “Update Your Name”- Navigate to Profile
- Edit the Full Name field
- Click Save Changes
Your name appears in transaction records and member lists.
Change Your Email
Section titled “Change Your Email”- Navigate to Profile
- Edit the Email field
- Click Save Changes
- Check your new email for a verification link
- Click the link to confirm the change
Important: The change remains pending until you verify the new email. You can continue using Allowealth during this period.
Cancel Email Change
Section titled “Cancel Email Change”If you change your mind before verifying:
- Look for the pending change banner on your Profile page
- Click Cancel Change
- Your email reverts to the previous address
Resend Verification Email
Section titled “Resend Verification Email”If the verification email does not arrive:
- Wait 60 seconds (rate limit applies)
- Click Resend Email
- Check spam/junk folders
- Verify the email address has no typos
Security
Section titled “Security”Protect your account with multiple security layers.
Multi-Factor Authentication (MFA)
Section titled “Multi-Factor Authentication (MFA)”MFA requires a second verification step when logging in. Even if someone obtains your password, they cannot access your account without the second factor.
Enable MFA
Section titled “Enable MFA”- Navigate to Security
- Find the Multi-Factor Authentication section
- Click Enable MFA
- Enter your password to confirm
- Add the setup key to your authenticator app
- Enter the 6-digit code from the app
- Click Verify
Save Backup Codes
Section titled “Save Backup Codes”After enabling MFA, you receive backup codes:
- Click Download or Copy to save them
- Store in a secure location (password manager or physical safe)
- Each code works once if you lose access to your authenticator app
Warning: Without backup codes, losing your authenticator app can lock you out until you disable and reconfigure MFA from a verified session.
Disable MFA
Section titled “Disable MFA”- Navigate to Security
- Click Disable MFA
- Enter your password
- Confirm the action
Disabling MFA reduces account security. Keep MFA enabled unless absolutely necessary.
Regenerate Backup Codes
Section titled “Regenerate Backup Codes”- Navigate to Security
- Click Regenerate Codes
- Enter your password
- Save the new codes
- Old codes become invalid
Regenerate codes if you:
- Used most of your backup codes
- Suspect someone obtained your codes
- Lost your stored codes
Connected Accounts
Section titled “Connected Accounts”View accounts linked to your Allowealth login:
- Google - Shows status and linked email
- Connected - Indicates active link
- Not Connected - Available to link
To connect Google:
- Sign in with your current account method
- Open Security
- In Connected Accounts, click Connect Account
- Complete the Google confirmation flow
To disconnect Google:
- Open Security
- In Connected Accounts, click Disconnect
- Confirm the change
If Google is your only usable sign-in method, Allowealth blocks unlinking to prevent lockout.
Passkeys
Section titled “Passkeys”Passkeys provide passwordless login using biometric authentication (fingerprint, face recognition) or hardware security keys.
Status: Passkey management is coming soon. The interface shows planned functionality.
API Keys
Section titled “API Keys”Generate API keys to access Allowealth from external applications and scripts.
Create an API Key
Section titled “Create an API Key”- Navigate to Security
- Find the API Keys section
- Click Generate API Key
- Enter a descriptive name (for example, “Personal Scripts”)
- Optionally set an expiration date
- Click Generate
- Copy the key immediately - it displays only once
Store API Keys Securely
Section titled “Store API Keys Securely”- Use a password manager
- Never commit keys to version control
- Never share keys in email or chat
- Treat keys like passwords
Revoke an API Key
Section titled “Revoke an API Key”- Find the key in the API Keys list
- Click Revoke
- Confirm the action
Revoked keys lose access immediately. Applications using the key will fail.
View Key Usage
Section titled “View Key Usage”The API Keys list shows:
- Name - Description you provided
- Prefix - First few characters of the key (for identification)
- Created - When you generated it
- Last Used - Most recent access
- Expires - Expiration date (if set)
Security Events
Section titled “Security Events”Recent security activity appears in the Security Events section:
- Logins from new devices or locations
- Password changes
- MFA setup or removal
- Passkey registration
Review this log periodically for unauthorized activity.
Best Practices
Section titled “Best Practices”Secure Your Account
Section titled “Secure Your Account”- Enable MFA - The single most effective security measure
- Use a strong password - Unique to Allowealth, 12+ characters
- Save backup codes - Store outside Allowealth
- Review security events - Check monthly for suspicious activity
- Revoke unused API keys - Minimize attack surface
Email Security
Section titled “Email Security”- Use a secure email provider
- Enable MFA on your email account
- Keep your Allowealth email current
- Watch for phishing attempts pretending to be Allowealth
Device Security
Section titled “Device Security”- Log out on shared computers
- Do not save passwords on public devices
- Use device lock screens
- Keep operating systems and browsers updated
Troubleshooting
Section titled “Troubleshooting”Cannot Enable MFA
Section titled “Cannot Enable MFA”- Ensure you have an authenticator app installed
- Check your device’s camera works for QR scanning
- Verify your system time is accurate (time drift breaks TOTP codes)
- Try manual code entry instead of QR scan
Lost Authenticator App
Section titled “Lost Authenticator App”- Use a backup code to log in
- Navigate to Security settings
- Disable MFA
- Re-enable MFA with your new device
- Generate new backup codes
If you have no backup codes and no verified session, you may need help from your workspace administrator.
API Key Not Working
Section titled “API Key Not Working”- Verify the key is copied completely (no extra spaces)
- Check if the key expired
- Confirm the key was not revoked
- Generate a new key if necessary
Email Verification Not Arriving
Section titled “Email Verification Not Arriving”- Check spam/junk folders
- Verify the email address has no typos
- Wait 5 minutes for delivery
- Click Resend after the cooldown period
- Try a different email address if problems persist
Related Features
Section titled “Related Features”- Settings - Manage workspace preferences and members
- Profile - Update personal information
- API Documentation - Technical reference for API key usage