Account security & login
Sign-in methods
Emergent supports five authentication methods to fit your workflow:
- Email + password - traditional username/password sign-in.
- Google OAuth - fast login with your Google account (see Google auth for configuration).
- Apple OAuth - secure sign-in with Apple ID.
- Phone OTP - SMS one-time passcode authentication (carrier rates apply).
- SSO - SAML or OpenID Connect for enterprise teams (Pro/Enterprise plans).
You can link multiple providers to the same Emergent account by signing in with each method while already authenticated. Once linked, any method grants access to your workspace.
Switching providers
If you signed up with email but want to use Google going forward, sign in with your email, then visit Settings → Account → Connected accounts and authorize Google. Both methods will then unlock the same workspace.
Resetting your password
Navigate to the sign-in screen
Click Sign In from the Emergent homepage.
Request a reset link
Select Forgot password? below the email field. Enter your email address and submit.
Check your inbox
You'll receive a password-reset email within a few minutes (check spam if it doesn't arrive). The link expires after 24 hours.
Set a new password
Click the link, enter a new password (minimum 8 characters), and confirm. You'll be signed in automatically.
Note
Password reset is only available for accounts that signed up with email + password. OAuth accounts (Google, Apple) inherit security from the identity provider and do not have Emergent passwords.
Changing your email address
Email addresses cannot be changed once an account is created. This immutability ensures audit integrity, billing consistency, and prevents accidental email collisions in team workspaces.
Workaround: GitHub migration
If you must switch to a new email:
- Export any critical projects or data you want to preserve.
- Create a new Emergent account with the desired email address.
- Transfer projects manually by cloning repositories or re-importing app definitions.
Team seats and billing
Deleting your old account and re-joining a team will consume a new seat. Contact support@emergent.sh if you need help coordinating a migration with minimal disruption.
Deleting your account
Account deletion is irreversible but includes a 45-day grace period during which your account is soft-deleted and can be restored.
Navigate to account settings
Click your avatar → Settings → Account.
Request deletion
Scroll to Danger zone and select Delete account. Confirm your password (or re-authenticate via OAuth).
Grace period begins
Your account is immediately deactivated. All apps, projects, and data are hidden but retained for 45 days.
Restore or purge
During the grace period you can sign in to restore your account with one click. After 45 days all data is permanently purged and cannot be recovered.
Permanent data loss
After the 45-day grace period, deletion is final. Export any critical projects, code, or databases before initiating deletion. See Database (MongoDB) for export instructions.
What happens to team workspaces?
- If you are the sole owner, the workspace is also soft-deleted. Transfer ownership to another member before deletion to preserve team resources.
- If you are a member, you are simply removed. The workspace and its apps remain unaffected.
Session and token security
Emergent uses industry-standard session management to protect your account:
| Feature | Detail |
|---|---|
| Session duration | 30 days of inactivity before auto-logout |
| Token storage | Secure HTTP-only cookies; tokens are never exposed to client JavaScript |
| Token rotation | Refresh tokens rotate on every use; stolen tokens expire within minutes |
| Device tracking | Active sessions are listed in Settings → Security with IP, browser, and last-seen timestamp |
| Remote logout | Revoke any session remotely (useful if you left a device signed in) |
Info
Emergent does not store plaintext passwords. All credentials are hashed with bcrypt (cost factor 12) and OAuth providers never share passwords with our platform.
Revoking sessions
Open security settings
Click your avatar → Settings → Security → Active sessions.
Review devices
Each row shows a device fingerprint, browser, IP address, and last activity timestamp.
Revoke unwanted sessions
Click Revoke next to any session you don't recognize or no longer use. That device will be logged out immediately.
Sign out everywhere
If you suspect unauthorized access, use Sign out all other sessions at the top of the list to invalidate every session except your current one. Change your password immediately afterward.
Best practices
- Enable two-factor authentication (2FA) if your OAuth provider supports it (Google, Apple both do). Emergent inherits 2FA from the identity provider.
- Review active sessions monthly, especially if you use shared or public computers.
- Use a password manager for strong, unique passwords on email-based accounts.
- Link multiple sign-in methods so you have a backup if one provider is unavailable.
Yes, on Enterprise plans. Contact support@emergent.sh to enable organization-wide 2FA enforcement. Members without 2FA will be prompted to configure it on their next sign-in.
If you've linked multiple sign-in methods, use an alternate provider. If OAuth is your only method and you lose access, contact support@emergent.sh with proof of ownership (billing receipts, project metadata) to regain access.
Yes. Personal access tokens (PATs) for the Emergent API follow the same rotation and expiry rules. Review and rotate tokens in Settings → Developer → API tokens. Tokens are scoped to specific permissions and can be revoked individually. See The Universal LLM Key for more on API security.

