Your account
Password and security.
Everything here changes how you get in. None of it is shown to anybody else.
Looking for your account on this device.
Signed in as
Apple gave us this address instead of your own. Mail sent to it is forwarded to your real inbox for as long as you leave the connection in place in your Apple ID settings.
This address has not been checked by email. This product does not send a confirmation, so nothing has proved it is yours. It is also the only way back in if you forget your password, so it is worth being sure it is right.
Your password
How you sign in
The ways that currently reach this account. Anything not listed here cannot get in.
Devices and sessions
Signing in creates a session on that device and nowhere else. There is no list of them here, because the account service does not publish one. What it does give us is a way to end all of them at once.
Sign out everywhere ends every session this account has, on every device, immediately, including the one you are reading this on and any access token already handed out. Measured against the live service.
What is true here
Five statements, each one checked against this product before it was written down.
- Your password goes straight to Supabase over HTTPS. It is typed here and posted to our authentication provider. It does not pass through an Invictus server on the way, and no Invictus code ever sees it.
- We never store it, anywhere. Not in this browser, not in a URL, not in a log. Supabase keeps a one-way hash, so there is nowhere in this product it exists in a form that can be read back.
- Nothing else on this page ever sees it either. It is not sent to a breach-checking service. The list of common passwords is embedded in this page and checked in your browser, so the password does not have to travel to be judged.
- Changing your password ends every other session immediately. Any other device that was signed in is signed out at the moment you press save. This one was measured against the live service rather than inferred from the documentation.
- Your current password is re-checked with the server. Being signed in is not treated as proof of who is sitting at the keyboard, so a change needs the password itself, verified by a sign-in against Supabase in a throwaway session that is discarded straight afterwards.
Signed out everywhere.
Every session on every device has ended. Nothing was deleted. Your answers, XP and lesson plans are waiting for the next time you sign in.
Sign in again