Skip to main content

Account security

A Starfire account can hold conversations, projects, organization access, billing context, and developer resources, so account security affects more than the chat interface.

Verify your identity

Keep the account email current and complete verification when required. Recovery flows depend on Starfire being able to distinguish the legitimate account owner from an unverified address.

Protect the password

Use a unique password and do not reuse API keys or other secrets as an account password. Never share a password through a chat, support message, or project note.

Review sessions and devices

If a device is lost or a session looks unfamiliar, revoke it from the available account-security controls or contact an authorized administrator when necessary.

Recovery events

Password-reset and verification links should be treated as sensitive, short-lived account actions. If you did not request one, do not use it.

Developer access is separate

API keys and service-account credentials can continue to exist independently from browser sessions. If the account may be compromised, review developer resources as well as interactive sessions.

Organization access

If a compromised account belongs to an organization, organization administrators should review the member’s role, project access, and developer resources in addition to normal account recovery.

Security holds

Starfire’s administration model can use security-specific account states so an issue can be contained while it is investigated without immediately deleting the account.
If you believe a credential is exposed, reduce access first—revoke the session or developer credential—then investigate what happened. Waiting for certainty can increase the impact.

Sessions & devices

Learn how Starfire separates account identity from individual sessions.