Available controls
Password
Use at least 12 characters. Previously used and known compromised passwords are rejected.
TOTP
Enroll an authenticator app and store the single-use recovery codes offline.
Passkeys
Add a device-bound or synced passkey with user verification.
Sessions
Review active sessions, revoke one session, or sign out everywhere.
Session behavior
Browser authentication uses an opaqueHttpOnly session cookie. State-changing browser requests also require a CSRF token. Sessions have an inactivity limit and an absolute lifetime, and are bound to the browser’s user-agent context.
Recommended baseline
- Add at least one passkey or enable TOTP.
- Store recovery codes away from the device used for sign-in.
- Revoke unfamiliar sessions immediately.
- Use unique API keys per workload instead of sharing a human credential.
- Notify support@aptranet.com if you suspect account or credential compromise.