Support

Account security & login

Sign-in methods

Emergent supports five authentication methods to fit your workflow:

  • Email + password - traditional username/password sign-in.
  • Google OAuth - fast login with your Google account (see Google auth for configuration).
  • Apple OAuth - secure sign-in with Apple ID.
  • Phone OTP - SMS one-time passcode authentication (carrier rates apply).
  • SSO - SAML or OpenID Connect for enterprise teams (Pro/Enterprise plans).

You can link multiple providers to the same Emergent account by signing in with each method while already authenticated. Once linked, any method grants access to your workspace.

Switching providers

If you signed up with email but want to use Google going forward, sign in with your email, then visit Settings → Account → Connected accounts and authorize Google. Both methods will then unlock the same workspace.

Resetting your password

1

Navigate to the sign-in screen

Click Sign In from the Emergent homepage.

2

Request a reset link

Select Forgot password? below the email field. Enter your email address and submit.

3

Check your inbox

You'll receive a password-reset email within a few minutes (check spam if it doesn't arrive). The link expires after 24 hours.

4

Set a new password

Click the link, enter a new password (minimum 8 characters), and confirm. You'll be signed in automatically.

Note

Password reset is only available for accounts that signed up with email + password. OAuth accounts (Google, Apple) inherit security from the identity provider and do not have Emergent passwords.

Changing your email address

Email addresses cannot be changed once an account is created. This immutability ensures audit integrity, billing consistency, and prevents accidental email collisions in team workspaces.

Workaround: GitHub migration

If you must switch to a new email:

  1. Export any critical projects or data you want to preserve.
  2. Create a new Emergent account with the desired email address.
  3. Transfer projects manually by cloning repositories or re-importing app definitions.

Team seats and billing

Deleting your old account and re-joining a team will consume a new seat. Contact support@emergent.sh if you need help coordinating a migration with minimal disruption.

Deleting your account

Account deletion is irreversible but includes a 45-day grace period during which your account is soft-deleted and can be restored.

1

Navigate to account settings

Click your avatar → Settings → Account.

2

Request deletion

Scroll to Danger zone and select Delete account. Confirm your password (or re-authenticate via OAuth).

3

Grace period begins

Your account is immediately deactivated. All apps, projects, and data are hidden but retained for 45 days.

4

Restore or purge

During the grace period you can sign in to restore your account with one click. After 45 days all data is permanently purged and cannot be recovered.

Permanent data loss

After the 45-day grace period, deletion is final. Export any critical projects, code, or databases before initiating deletion. See Database (MongoDB) for export instructions.

What happens to team workspaces?

  • If you are the sole owner, the workspace is also soft-deleted. Transfer ownership to another member before deletion to preserve team resources.
  • If you are a member, you are simply removed. The workspace and its apps remain unaffected.

Session and token security

Emergent uses industry-standard session management to protect your account:

FeatureDetail
Session duration30 days of inactivity before auto-logout
Token storageSecure HTTP-only cookies; tokens are never exposed to client JavaScript
Token rotationRefresh tokens rotate on every use; stolen tokens expire within minutes
Device trackingActive sessions are listed in Settings → Security with IP, browser, and last-seen timestamp
Remote logoutRevoke any session remotely (useful if you left a device signed in)

Info

Emergent does not store plaintext passwords. All credentials are hashed with bcrypt (cost factor 12) and OAuth providers never share passwords with our platform.

Revoking sessions

1

Open security settings

Click your avatar → Settings → Security → Active sessions.

2

Review devices

Each row shows a device fingerprint, browser, IP address, and last activity timestamp.

3

Revoke unwanted sessions

Click Revoke next to any session you don't recognize or no longer use. That device will be logged out immediately.

Sign out everywhere

If you suspect unauthorized access, use Sign out all other sessions at the top of the list to invalidate every session except your current one. Change your password immediately afterward.

Best practices

  • Enable two-factor authentication (2FA) if your OAuth provider supports it (Google, Apple both do). Emergent inherits 2FA from the identity provider.
  • Review active sessions monthly, especially if you use shared or public computers.
  • Use a password manager for strong, unique passwords on email-based accounts.
  • Link multiple sign-in methods so you have a backup if one provider is unavailable.

Yes, on Enterprise plans. Contact support@emergent.sh to enable organization-wide 2FA enforcement. Members without 2FA will be prompted to configure it on their next sign-in.

If you've linked multiple sign-in methods, use an alternate provider. If OAuth is your only method and you lose access, contact support@emergent.sh with proof of ownership (billing receipts, project metadata) to regain access.

Yes. Personal access tokens (PATs) for the Emergent API follow the same rotation and expiry rules. Review and rotate tokens in Settings → Developer → API tokens. Tokens are scoped to specific permissions and can be revoked individually. See The Universal LLM Key for more on API security.

Was this page helpful?

Related pages