Account
The Account page (the account menu at the top of the dashboard) shows your sign-in address, second factors, role and plan, and links to Security, API tokens and Activity. It also holds Preferences, Error reports, Export your data and Delete account.
Anything that changes a credential, starts an export or deletes the account needs a sign-in within the last five minutes; the dashboard asks you to confirm if it has been longer.
Sign-in credentials
Section titled “Sign-in credentials”Account → Security holds how you sign in. opdns runs its own sign-in; there is no third-party identity provider.
| Credential | Notes |
|---|---|
| Passkeys | the primary credential; add one per device or security key |
| Password | with an authenticator code when TOTP is on |
| Authenticator app (TOTP) | six-digit codes from any TOTP app |
| Recovery codes | ten single-use codes, issued with your first second factor; regenerate to invalidate the old set |
Password rules
Section titled “Password rules”A new password (at sign-up, when you change it, reset it or recover the account) must be 12 to 128 characters. That is the only rule: no required digits, symbols or mixed case. Characters are counted as Unicode code points, so an emoji or an accented letter counts as one, and the password is used exactly as you typed it, spaces included, without being shortened or normalised. A passphrase of a few unrelated words is long and easy to remember.
Under the field, a strength meter estimates how easy the password is to guess, from Very weak to Very strong, and repeats the estimator’s advice (for example that a password is a common one, or that it contains your email address). It only advises: a weak password that meets the length rule is accepted. The meter runs in your browser and loads when you first type in the field; nothing you type is sent anywhere to be scored. opdns does not check new passwords against lists of breached passwords: how strong to make it is your choice.
Passwords set before the 12-character minimum keep working for sign-in; the rule applies the next time the password is set.
Every password field in the dashboard has a Show button that reveals what you typed, so you can check it before submitting. It is a real button (keyboard and screen readers report whether it is pressed); it changes only whether the field is masked, not its autocomplete hints, and the field is masked again when you submit the form.
An authenticator code works once. If a code that was already used is sent again, for example by someone who watched you type it, the sign-in is refused, the attempt is recorded in Activity and you get a security notice.
A second factor is required
Section titled “A second factor is required”An account needs a passkey or an authenticator app within 7 days of sign-up. After that, for an account that has neither, signing in with the password alone gives a session that can only add one: the dashboard sends you to Security, and everything else answers that a second factor is needed first. Adding the passkey or authenticator app lifts that restriction for the session you added it from only; any other session that signed in with the password alone stays restricted until it signs in again.
Security notices
Section titled “Security notices”Changes to how you sign in are emailed to you, with the time, so a change you did not make does not go unnoticed:
- an authenticator app added or removed;
- a passkey added or removed;
- new recovery codes generated (the old ones stop working);
- a sign-in attempt that reused an authenticator code, which was refused (at most five such emails a minute);
- a password change, reset or account recovery (these have their own emails).
Each notice says there is nothing to do if it was you, and otherwise to sign in, remove what you do not recognise, sign out the other sessions and change your password, with a link to Sessions.
A password change, a password reset or an account recovery also ends every reset and recovery link sent before it, so a link requested earlier, by you or by someone else, stops working.
Failed sign-ins
Section titled “Failed sign-ins”Password sign-in slows down after a failure instead of locking the account: the next attempt from the same address, or for the same email address, waits 100 ms, doubling with each further failure up to 5 seconds. A successful sign-in clears the delay for the account. Passkey sign-in is never delayed. After ten failed attempts on your account within an hour, you get one email with the number of attempts, the latest time and address, and links to reset your password and review your sessions (at most one such email an hour).
Account recovery
Section titled “Account recovery”If you lost your authenticator app or your passkeys, you can recover the account with the email address and one of your saved recovery codes. Email alone never unlocks an account with a second factor; without a recovery code, contact support from the address on the account.
- On the sign-in page, choose Lost access? (next to Forgot your password?; it is also on the password reset page). Enter your email address and choose Send recovery link.
- The page always answers Check your inbox. If the address has an account with an unused recovery code, a link arrives; it works once and for one hour. An account without an unused recovery code gets no email.
- Open the link, enter a recovery code (
xxxx-xxxx-xxxx-xxxx; case, spaces and dashes do not matter) and a new password twice, and choose Recover account.
Recovering sets the new password, spends the recovery code, removes the authenticator app, signs out every session and stops any other recovery or password reset link from working. Passkeys and API tokens are kept. The page says how many sessions were signed out and how many recovery codes are left, and an email confirms what changed. Then sign in with the new password and set up two-step sign-in again: add an authenticator app or a passkey and generate new recovery codes.
A wrong or already used code keeps the form (That recovery code did not work) and the link stays usable; repeated wrong codes are limited. An expired or used link says so, with a Start again link. Every step is recorded in Activity.
If you only forgot your password, use Forgot your password? instead: it emails a reset link, and an account with a second factor also asks for an authenticator or recovery code.
Sessions
Section titled “Sessions”The Sessions section of the Security page lists every browser signed in to your account, most recently used first:
| Column | Shows |
|---|---|
| Client | browser and system, from its user agent; This browser marks the one you are using |
| Address | the IP address it last used, or unknown |
| Last active | when it last made a request |
| Signed in | when the session started, and when it expires |
Sign out ends one session; for the current browser the button is Log out. Sign out all other sessions ends every session but this one, on its next request. Neither affects API tokens: revoke those on the API tokens page.
A session lasts at most 30 days from sign-in and ends after 7 days without use. Once a day the dashboard’s session token is replaced by a new one behind the scenes; you stay signed in.
Activity
Section titled “Activity”Account → Activity is your organisation’s audit log, newest first: sign-ins and failed attempts, failed-sign-in emails, password, passkey, authenticator and recovery-code changes, account recovery, sessions signed out, API tokens created and revoked, profiles, linked IPs, nodes added, enrolled and revoked, devices changed, preference changes, exports and deletion, and the list reports you sent. Failures are recorded too:
| Entry | Means |
|---|---|
| Password change refused, wrong current password | someone tried to change the password without knowing the current one |
| Wrong second-factor code | a wrong code while resetting the password, or while confirming or removing the authenticator app |
| Authenticator code reused, refused | a code that had already been used was sent again; see above |
| Each entry shows when, what, who (You, another account, an | |
| API token, DDNS update or opdns itself), on what, and its details (such | |
| as the address and browser). A profile change records what changed: each | |
| setting with its old and new value, and the rules or lists added and | |
| removed (up to 20 of each). Load more fetches older entries. |
If you see something you do not recognise, change your password and sign
out the other sessions on Security. The same log is in the
export and at GET /v1/auth/audit (scope
account:read).
Operator pages
Section titled “Operator pages”If your account is an opdns operator, the Operator pages (operator and source blocks, the operator audit) need a session signed in with a passkey, or with a password and an authenticator code. A session signed in with the password alone sees Operator pages need a sign-in with a passkey or authenticator app, with a link to Security, instead of the page: add a passkey or an authenticator app there if the account has neither, then sign out and sign in again with it. The rule does not apply on a development server. See Admin tools.
Preferences
Section titled “Preferences”Email me when a self-hosted node goes offline sends the
node offline and back online emails.
It is on by default and saves as soon as you flip it. Only owners receive
these emails; other members see a note saying so. The switch is read-only
while a deletion is pending. With the API: GET and PATCH /v1/auth/me/preferences ({"alerts":{"node_offline":false}}), with a
session.
Error reports
Section titled “Error reports”When the dashboard crashes it can tell opdns what broke. Send error reports from this browser turns that off for this browser. A report holds the dashboard version, the page with ids removed, and the error and where in the code it happened: never domain names, IP or email addresses, or profile settings. Only some errors are sent (about half, at most five per page load, no duplicates), and nothing reaches a third party.
API tokens
Section titled “API tokens”Account → API tokens creates tokens for the API, each with a name,
scopes and an optional expiry. The secret (opdns_…) is shown once. See
Authentication.
Export your data
Section titled “Export your data”Export your data builds a zip of everything opdns holds about you:
| File | Holds |
|---|---|
README.md, manifest.json |
what each file holds; log row counts per profile, and whether a profile’s logs were cut at the row limit |
account.json |
your account and sign-in methods (passkey names and dates, recovery codes left); never password hashes, seeds or keys |
sessions.json |
your sessions (device, address, sign-in method); never session secrets |
tokens.json |
API token metadata (names, scopes, dates; never the secrets) |
audit_log.ndjson |
your account’s audit log |
profiles/<id>/profile.json |
the profile document, in the format a standalone node loads |
profiles/<id>/metadata.json, rules.json, linked_ips.json |
the profile’s name and dates, its rules, its linked IPs |
profiles/<id>/devices.json, nodes.json |
its devices with their display names, and its self-hosted nodes |
profiles/<id>/logs.ndjson |
its cloud query logs within retention, newest first, one JSON object per line, up to a row limit per profile. Fields you chose not to log were never stored, so they are not here either |
The archive is built in the background. You get an email when it is ready, and the download stays available for 24 hours. You can have one export in progress and start one a day. Logs held only on a self-hosted node are not in it; they are in the node’s own SQLite file.
The same export is available through the API (POST /v1/auth/me/export,
with a session only). See the
data rights process.
Delete your account
Section titled “Delete your account”Delete account first explains what happens, then asks you to type your email address and confirm with your password, an authenticator code or a recovery code (a session signed in with a passkey needs none of them). Download an export first if you want a copy.
Right away:
- every session, this one included, and every API token is revoked, so you are signed out;
- your profiles stop resolving: queries to their addresses are refused
(
REFUSED) on every device that uses them; - your self-hosted nodes are revoked and disconnected. They keep their local data; erase it on the node;
- log batches waiting for your nodes are discarded;
- a confirmation email gives the date of erasure.
For 7 days you can change your mind. Sign in and cancel the deletion: your profiles are restored and resolve again. Sessions, API tokens and nodes stay revoked; enrol your nodes again. During these 7 days you can only sign in to see the deletion, cancel it, sign out, or download an export made earlier.
After 7 days your account, your profiles’ configuration and their query logs (including the hourly counters) are erased. Entries in the audit log are kept with your identity removed. Backups are not edited; the copies in them expire within 30 days. Profile ids are never reused.
An account whose organisation has other members cannot be deleted this way. See the privacy policy and the data rights process.