> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Account security

> Protect your Aptranet account with strong passwords, TOTP, passkeys, and session management.

Aptranet Identity protects Management Console sessions. API keys use a separate non-human authentication path.

## Available controls

<CardGroup cols={2}>
  <Card title="Password" icon="lock-keyhole">
    Use at least 12 characters. Previously used and known compromised passwords are rejected.
  </Card>

  <Card title="TOTP" icon="scan-line">
    Enroll an authenticator app and store the single-use recovery codes offline.
  </Card>

  <Card title="Passkeys" icon="fingerprint">
    Add a device-bound or synced passkey with user verification.
  </Card>

  <Card title="Sessions" icon="monitor-smartphone">
    Review active sessions, revoke one session, or sign out everywhere.
  </Card>
</CardGroup>

## Session behavior

Browser authentication uses an opaque `HttpOnly` session cookie. State-changing browser requests also require a CSRF token. Sessions have an inactivity limit and an absolute lifetime, and are bound to the browser's user-agent context.

## Recommended baseline

* Add at least one passkey or enable TOTP.
* Store recovery codes away from the device used for sign-in.
* Revoke unfamiliar sessions immediately.
* Use unique API keys per workload instead of sharing a human credential.
* Notify [support@aptranet.com](mailto:support@aptranet.com) if you suspect account or credential compromise.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.