Two Minute Reports Logo
Account Security

Confirm It's You

Why the Hub asks you to confirm it's you before sensitive actions, which actions trigger it, how long a confirmation lasts, and which methods you can confirm with.

Some actions in the Hub are worth a second check even when you're already signed in, because of what someone could do with them if they sat down at your unlocked computer or copied your browser session. Before those actions the Hub shows a short dialog titled Confirm it's you.

The small heading above the title names the action, such as Create API key, and the line under the title names exactly what you are approving, such as "Looker sync" for Northwind Digital or Claude (claude.ai) to Northwind Digital. Check that line. If it is not what you meant to do, click Cancel and nothing happens.

When You're Asked

Changes to How You Sign In

You're asked unless you confirmed, or signed in, in the last 5 minutes:

  • Setting a password, or changing it
  • Turning two-factor authentication on or off
  • Adding or removing a passkey
  • Removing or changing your authenticator app
  • Generating new recovery codes

Lasting Access, Team-Wide Changes and Billing

You're asked unless you confirmed, or signed in, in the last 15 minutes:

  • Creating an API key, or giving an existing key more access than it had
  • Connecting an AI app such as Claude or ChatGPT to a team over MCP (when you click Allow)
  • Turning a team's 2FA requirement on or off
  • Opening the billing portal, or cancelling the subscription

Once you've confirmed, you can carry on with these for 15 minutes without being asked again, and each of them restarts the 15 minutes, up to 2 hours after you confirmed. After that, the next one asks again.

The Hub asks when you click the final button, not when you open the form, so you never lose what you typed: confirm, and the action carries on.

Not Asked

Everyday work never asks. Neither do renaming a passkey, revoking or narrowing an API key, inviting or removing members, changing roles or seats, or other team settings.

Opening billing. Browsers block a new tab that opens after a pause, so once you've confirmed, the Hub shows Billing portal is ready. Click Open billing portal to go to it.

How You Confirm

The dialog opens on the method you used most recently. Use another method lists the others you have.

If You Have 2FA

You confirm with a second-step method:

  • Your passkey: click Use passkey and confirm with your fingerprint, face or screen lock. If the passkey is on your phone, choose Use a phone or tablet in the browser window and scan the QR code. See Passkeys.
  • Your authenticator app: type the 6-digit code and click Confirm.

Your password, Google, Microsoft and email codes are not offered: with 2FA on, they would be a weaker check than the one you chose.

A recovery code is accepted for only two actions: turning 2FA off and changing your authenticator app. Those are what someone who has lost their phone needs to do. Every other action needs a passkey or the app.

If You Don't Have 2FA

You confirm with a way you sign in:

  • Enter your password, if your account has one
  • Continue with Google or Continue with Microsoft, if you sign in with them. A Google or Microsoft window opens; sign in as the same account you use for Two Minute Reports. Microsoft only appears once you have signed in with it at least once.
  • Email me a code: we send a 6-digit code to your account email. It lasts 10 minutes and allows 5 tries. It is a different kind of code from the one you sign in with, so a sign-in code cannot be used here.

Confirming with Google or Microsoft never signs anyone in or links another account. If you pick a different Google or Microsoft account, the Hub says That's a different Google account (or Microsoft account), and nothing is changed.

If your browser blocks the Google or Microsoft window, the dialog shows a button to open it again.

Wrong Codes and Passwords

  • A wrong code leaves your digits on screen so you can see what you typed: That code didn't match. Enter the code your app shows now.
  • After 5 wrong codes in one dialog, or 10 in 15 minutes across signing in and confirming, the Hub says Too many attempts and asks you to try again in 15 minutes. Closing and reopening the dialog does not reset this.
  • Wrong passwords count toward the same account lock as wrong passwords at sign-in.

Who Can't Confirm

  • Support. When the Two Minute Reports support team is helping inside your account, they cannot confirm on your behalf, so they cannot change security settings, API keys or billing. They see Support can't do this. Ask the person whose account it is to do it from their own sign-in.
  • API keys and connected apps. Security settings, sessions, API keys and billing can only be changed from a Hub sign-in, never by an API key or a connected app.

Trusted Browsers Still Confirm

Trusting a browser for 30 days only skips the second step at sign-in. It never skips Confirm it's you.

Copyright © 2026