# Account and security

> Manage your profile, password, two-factor authentication, sessions and API keys from Settings in the dashboard.

Source: https://docs.coritan.com/account/

In the dashboard:

- /dashboard/settings: https://www.coritan.com/dashboard/settings

Your Coritan account holds your services, your credit and your invoices. You sign in to it with an email address and a password, and you keep its details and its security in **Settings**. To open it, select **Settings** in the sidebar, or select your initials at the top right and then **Settings**.

**Settings** has three tabs:

**Profile**
: Your name and company, the currency you pay in and your billing country.

**Security**
: Two-factor authentication, your password and the session in this browser.

**API keys**
: Keys you can create and revoke. The API does not accept them yet.

## Sign in and out

- [Sign in to your account](/account/sign-in/), with a code from your authenticator app if you use one.
- [Change or reset your password](/account/password/).
- [Sign out and end sessions](/account/sessions/).

## Keep your details up to date

- [Update your profile](/account/profile/): your name, company, currency and country.
- [Currencies and countries](/billing/currencies-and-regions/) lists what you can choose.

## Protect the account

- [Turn on two-factor authentication](/account/two-factor-authentication/).
- [Manage API keys](/account/api-keys/).
- [Link your account to a Coritan staff account](/account/staff-link/), if you work at Coritan.

## Billing

An account costs nothing on its own. You pay for the services you order, from your credit balance or a saved payment method, as [Billing](/billing/) explains.

## Limits

- You cannot change your email address or your billing mode in the dashboard. [Contact support](/support/) to change them, or to close the account.
- The dashboard can only show the session in the browser you are using. [Sign out and end sessions](/account/sessions/) explains how to end the others.
- Two-factor authentication is optional, and it uses an authenticator app. Coritan sends no codes by text message or email.
- The API accepts the access token that signing in returns. [Authentication](/api/authentication/) has the details.
