Account Settings
Manage your AnyRouter profile, email addresses, authentication methods, and connected devices.
Your account is the root of everything you do on AnyRouter — the keys you mint, the organizations you belong to, the credits on your balance, and the logs of every request. If you lose access to it, or if a stale session lingers on a device you no longer control, all of that is exposed. Account settings is where you keep that root secure: manage your profile, add multiple ways to sign in, verify email addresses, and revoke sessions the moment something looks wrong.
Overview
There are two entry points:
| Page | URL | Use it for |
|---|---|---|
| Overview | /dashboard/settings | A read-only summary of your profile, contact details, security posture, and connected accounts — a quick check. |
| Editor | /dashboard/account | The full editor where you change your name, manage emails, add authentication methods, sign sessions out, and delete the account. All edits happen here. |
Profile and field-level changes save as soon as you confirm the field — there is no separate "save" button. Leaving a field commits the change.
How it works
Profile
Your profile is the identity AnyRouter shows alongside your usage logs, organization memberships, and team-facing surfaces.
- Name. Shown in the dashboard header, org member lists, and audit entries. Changes propagate immediately but do not rewrite past audit logs.
- Avatar. Uploaded images are cropped to a square. If you sign in with an OAuth provider that supplies a photo (e.g. Google), that photo is used until you upload your own.
- Username. Optional; appears as
@your-nameon the profile card. Not used for authentication — you always sign in with email, an OAuth provider, or a passkey. - Primary email. The single address used for billing receipts, security alerts, and account recovery (see Email addresses).
Authentication methods
AnyRouter supports several sign-in methods on the same account; any one is enough to get in. Add more to reduce lock-out risk.
| Method | How it works | Notes |
|---|---|---|
| Password | Email + password. Add, change, or remove from the account editor. | Minimum length enforced; breached passwords rejected. Removing your only method is blocked. Use Forgot password to reset via your primary email. |
| Magic link | AnyRouter emails a one-time sign-in link. | Available automatically once you have a verified email — no toggle. Links expire quickly and are single-use. |
| OAuth providers | Sign in with Google, GitHub, or Microsoft. | Connect from Connected accounts. AnyRouter requests only email, name, and avatar — never inbox, repos, or calendar. Cannot disconnect your only method. |
| Passkeys | WebAuthn (Face ID, Touch ID, Windows Hello, hardware key, password manager). | Phishing-resistant. Name each passkey (e.g. MacBook Pro). Add at least two so losing one device doesn't lock you out. |
Passkeys are the modern, phishing-resistant alternative to passwords, and pair well with magic links for a convenient-yet-secure setup. Adding two passkeys — say your laptop and your phone — means losing one device never locks you out.
Email addresses
Your account can hold multiple emails. Exactly one is the primary; the rest are verified secondaries.
The primary email is used for sign-in (magic links, password resets), security notifications (new-device sign-ins, password and auth-method changes), billing (invoices, receipts, balance alerts), and account recovery. Secondary emails are verified addresses linked to your account — useful for receiving magic links at both a work and personal address, or for linking OAuth providers whose email differs from your primary. Secondaries do not receive billing or security notifications; promote one to primary to move those.
Active sessions and devices
A session is created each time you sign in on a browser or device, and keeps you signed in across reloads. The Active sessions list shows every browser and device holding a valid session:
- Device — OS and browser (e.g. macOS · Safari).
- Location — approximate city and country from the sign-in IP.
- Last active — the most recent request from this session.
- Current session — the one you're using now, labelled and not revocable without signing yourself out.
API keys are not affected by session revocation — they are separate credentials with their own lifecycle. Signing out of all sessions does not rotate your keys. To rotate keys, go to the API keys page.
Two-factor authentication
If you sign in with a password, we strongly recommend a second factor. 2FA requires a one-time code from an authenticator app (1Password, Authy, Google Authenticator) in addition to your password.
- Enable — scan the QR code and enter the 6-digit code. AnyRouter shows one-time backup codes; store them safely. Each backup code works once.
- Disable — requires a current 2FA code.
- Regenerate backup codes — invalidates the previous set.
If you use a passkey, 2FA is not required — passkeys already combine "something you have" (the device) with "something you are" (biometric) into a single phishing-resistant step.
Email preferences
AnyRouter sends account emails (welcome, plan and credit notices) and, separately, a periodic usage-digest email. There's no in-dashboard toggle for these today — each email carries a one-click Unsubscribe link in its footer that either opts you out of that specific email type or out of all non-essential AnyRouter email. Security and billing-critical messages (receipts, new-device sign-in alerts) are not affected by unsubscribing.
Connected accounts
This section lists the OAuth providers linked to your account, each showing the provider name and the email it identifies you by. Disconnect removes the link; the next sign-in with that provider starts a fresh consent flow. Connecting a provider that returns an already-linked email replaces the old token silently — no duplicates.
Configure
Add an email address
- Click Add email and enter the address.
- AnyRouter sends a verification link — open the email and click it.
- Once verified, the address appears in your secondary emails.
Unverified emails cannot be used for sign-in or promoted to primary, and are removed automatically after a few days if not verified.
Promote or remove an email
- Make primary — click Make primary next to a verified secondary. Billing and security notifications immediately move to it; the previous primary is demoted to secondary and stays verified.
- Remove — click the trash icon. You cannot remove the primary (promote a different address first). Removing an email also disconnects any OAuth provider linked through it.
Revoke a session
- Single session — click Sign out on any entry to invalidate it immediately. The next request from that browser or device is rejected. Use this for a session you don't recognize, a public computer you forgot to sign out of, or a lost device.
- Everywhere — Sign out of all other sessions revokes every session except your current one. The fastest way to recover from a suspected compromise; pair it with rotating your password or adding a passkey.
Delete your account
Deleting your account is permanent — no undo, no soft-delete window.
- Open the Account page.
- Scroll to the Danger zone at the bottom.
- Click Delete account.
- Re-enter your password (or complete a passkey challenge).
- Type the confirmation phrase exactly as shown.
You'll be signed out immediately and the account becomes unrecoverable.
What gets deleted immediately: your profile (name, avatar, username) and all email addresses; all authentication methods (password, passkeys, OAuth links, 2FA, backup codes); all API keys you personally own (active requests begin failing with 401 Unauthorized within seconds); all presets you authored (anyone referencing @preset/<slug> gets "preset not found"); all conversation history and usage logs scoped to your user; any BYOK credentials (also revoke them on the upstream provider); and any unspent personal credits (non-refundable on deletion).
Organization memberships: if you are a regular member, you are removed and the organization is unaffected. If you are the sole owner of an organization, deletion is blocked until you transfer ownership or delete the organization — the UI tells you which orgs need attention (see Organizations). Organization-owned keys, presets, credits, and logs always stay with the organization.