Docs Cloud Account Security

Cloud account security

Mockarty Cloud keeps a new account limited until you confirm its email address. Creating an account does not sign you in or create a Personal Space immediately.

Verify your email

The sign-in and registration screens show available external sign-in providers
as a compact row of icons. Hover over an icon or focus it with Tab to identify
the provider; press Enter to continue. Only configured providers are shown.

  1. Open the Cloud cabinet and choose Create account.
  2. Enter your name, email and password, then accept the terms.
  3. Open the verification link from the email.
  4. Return to the cabinet and sign in.

New passwords need at least eight characters. Sign-in checks the password you
already have; the registration hint is shown only while creating an account.
If sign-in is temporarily rate-limited, wait before trying again. Attempts
for a different account on the same office network do not use
up this account’s attempt allowance; a separate network-wide safety limit still applies.

If the link expires, try to sign in and choose Send a new verification email. The cabinet always shows the same request result, whether or not an account exists for that address.

Recover access

On the sign-in screen, choose Forgot password?. Enter your email and follow the link in the message. After a successful reset, existing sessions are signed out.

The link is single-use and expires. Requesting a new one invalidates the old link. Mockarty never emails a temporary password; choose your new password on the recovery screen. For privacy, requesting recovery does not reveal whether the address belongs to an account.

Profile picture

Open the account menu in the top-right corner and choose Profile and security. Under Profile picture, choose Upload picture and pick a PNG, JPEG or WebP file up to 5 MB. Mockarty crops it to a square, scales it down and saves a fresh copy, so nothing else from the original file (camera details, location) is kept. The picture replaces your initials in the header, and people who share a Space with you see it next to your name in the member list; nobody else can open it.

Remove deletes the picture and brings your initials back. The picture is part of your personal data: it is included in the privacy export and deleted together with the account.

Change your sign-in email

In Profile → Change email, enter the new address and choose Send verification. The current sign-in address remains active while confirmation is pending.

  1. Open the first link sent to your current mailbox. If you have already enrolled two-factor authentication, you can enter a current authenticator code or one of your saved single-use backup codes instead of using the first email.
  2. Open the second link sent to the new mailbox within 24 hours.
  3. Sign in again using the new address. The old browser sessions and API tokens are revoked, and the old mailbox receives a security notice.

You can cancel a pending change from the same profile page. If the change has already completed, cancellation is refused; refresh your profile and sign in with the new address. A current password can be supplied as an additional check, but a password alone cannot replace current-mailbox or authenticator proof. If you cannot access either the old mailbox or an enrolled authenticator, do not assume that support can bypass this safeguard.

Two-factor authentication

In the cabinet, open Profile and find Two-factor authentication.

  1. Choose Enable 2FA.
  2. Add the displayed account to your authenticator app.
  3. Enter the six-digit code.
  4. Save the recovery codes in a secure place. Each recovery code works once.

To disable two-factor authentication, you must provide a current authenticator code.

After password verification, an account with 2FA enabled stays on the sign-in screen and asks for an authenticator or recovery code. A successful check creates one browser session.

Enrollment secrets, recovery codes, the resulting session credential, and SCIM provisioning tokens are one-time responses. The Cloud cabinet attaches a retry key automatically. If the connection drops or the server reports a temporary failure, use the same visible action again without changing the code: Cloud returns the already committed response instead of creating a second credential. A changed code starts a different request and never receives a previous response.

Passkeys (phishing-resistant sign-in)

In Profile → Passkeys you can register a passkey — the key your device itself
holds, unlocked by a fingerprint, a face or a device PIN. A passkey is the only
sign-in factor here that a fake page cannot relay: the signature it produces is
bound to the cabinet’s own address, so a copy of the page collects nothing usable.

  1. Choose Add a passkey and name it (for example, “Work laptop”).
  2. Confirm your identity: a recent sign-in is enough, otherwise enter your
    password, a one-time code or a recovery code.
  3. Approve the prompt from your device.

Each row in the list shows the name, when the passkey was added, whether it is
synced across your devices by your platform or bound to one device, and when it
was last used. Remove revokes it immediately; removing a passkey also asks to
confirm your identity.

Adding and removing a passkey both require a fresh confirmation, because each one
changes how your account proves who it is. A registered passkey also becomes an
option on the sign-in screen and in the confirmation prompt for sensitive
actions, next to your password and one-time code.

If you lose a passkey

Passkeys are an additional factor; they never replace your password or disable
two-factor authentication. Losing every passkey therefore does not lock you out:

  • with two-factor authentication enabled, sign in with your password and your
    authenticator app, or with one of your saved recovery codes;
  • without it, sign in with your password and register a new passkey while signed
    in.

Support cannot reset, remove or bypass a passkey for you — there is no such
operation in the product. This is deliberate: a support path that clears a second
factor is a way into any account.

Requirements

Passkeys need a browser and connection that support WebAuthn, and the cabinet must
be opened over HTTPS. If the installation has not configured its passkey address
(a relying-party identity), the feature reports that it is unavailable instead of
accepting a sign-in it cannot verify.

Confirm sensitive actions

Some actions ask you to confirm it is really you before they run: buying or refunding a plan, revealing a licence key, changing connectors or platform settings, deciding operator cases. If you signed in within the last five minutes, the confirmation is silent. Otherwise the cabinet asks for your password (or your one-time code when two-factor authentication is on).

One confirmation covers up to ten requests of the same action within five minutes, so working through a queue asks once, not every time. The confirmation is bound to your session and to that one action: it cannot be reused from another browser or for a different action. Five wrong passwords in a row pause confirmations for that session for fifteen minutes; signing in is not affected, and your other sessions are not affected either.

Review active sessions

Open Profile → Active sessions. Each entry shows a short device, browser and platform label, issue time and expiry. Mockarty Cloud does not show the raw session credential, network address or full browser header.

Use Revoke to sign out one other session, or Sign out other sessions to keep only the current browser. A session that does not belong to your account is never disclosed.

How many sessions you can have

One account is meant for one person’s several devices, not for a team’s shared login. Up to ten sessions live at once; signing in beyond that ends the oldest ones automatically.

So if many people know the account password, every new sign-in pushes out whoever signed in earlier. That is not a fault: to work together, add people to the Space — each then gets their own sign-in and their own role.

A session lives at most 24 hours from the moment it was issued, however actively it is used. It cannot be extended: once it expires you sign in again.

If sign-out cannot be confirmed because the connection or server fails, the cabinet stays open and tells you the session may still be active. Retry sign-out after reconnecting.

API tokens

Use API tokens in the Cloud cabinet for scripts and integrations. After creating a token, copy it before leaving the page: its plaintext is shown only once. The cabinet keeps this page open while issuance is in progress and asks before leaving or signing out with a visible token. Signing out removes the plaintext from the page. If the request reports success without showing a token, check the token list before creating another one.

Directory sync (SCIM)

On an Enterprise plan, Profile → Directory sync (SCIM) connects your identity provider (Okta, Entra ID, OneLogin) so that members are added and removed automatically instead of by hand.

Generate a provisioning token in that panel and copy it into your provider together with the base URL the cabinet shows:

<your Cloud address>/api/v1/cloud/scim/v2/<workspace id>

Your provider authenticates with that token as Authorization: Bearer <token> and manages the workspace’s members through the SCIM /Users endpoint: list, create, read, replace, patch and delete. The panel shows when the token was last used, so an idle integration is visible.

The token is shown only once, when it is created. The cabinet keeps the panel and Space open while issuance is in progress and asks before leaving or signing out with a visible token. Signing out removes the plaintext from the page. If a successful request shows no token, check directory sync status before trying again. Regenerate the token if it leaked, and revoke it to stop the sync at once — members already provisioned stay in the workspace until your provider removes them (or you do). Directory sync is an Enterprise capability: the panel is hidden on other plans.

Which workspace a request means

If your account belongs to more than one workspace, use Active workspace on the Workspace page. Team, runtime, desktop, subscription, webhook, and audit requests are then scoped to that selection.

API clients must send workspace_id for these operations when more than one workspace is accessible. Mockarty fails with workspace_required instead of guessing the first workspace. Omitting the field remains compatible only for an account with exactly one accessible workspace.

Cloud runs every Space on the shared Mockarty. The Mockarty in the cloud tab shows whether it is ready for this Space, and why not when it is not. A deployment inside your own perimeter is an on-premise instance, agreed separately — the cabinet leads you to sales rather than provisioning one for you.

On the Free plan, spending the shared allowance also requires an active Free-benefit affiliation and an owner, admin or editor role in that benefit group — the roles that hold a seat. Viewer and billing-only roles never spend the shared allowance and never take a seat. A member who leaves their last qualifying workspace releases that affiliation and starts the transfer cooldown; workspace ownership transfer does not silently transfer ownership of the billing account. After a transfer the previous owner stays on as an admin when the plan has a seat for them next to the new owner; when every seat is taken they become a viewer instead, and the response says so — a transfer is never refused for the seat its author is giving up.