Whether you want to update your password or check which devices are signed in to your account, both are waiting for you on the same page: Security. It's available on every account, Free plan included. Let's go through it in five steps.
1
Open the Security page
You reach both the same way: open Settings and pick Security from the Account group in the list on the left. The password form sits at the very top of the page and the Active Sessions section, the list of devices signed in to your account, at the very bottom, all on this one page.
Settings
Account
Profile
Account
Security
Workspace
Workspace
Billing
Invite Friends
Preferences
Appearance
Language & Region
Notifications
Modules
Calendar
Reminders
Security
Password and two-factor authentication settings.
Change Password
Two-Factor Authentication (2FA)
2FA Off
Enable two-factor authentication to secure your account
Connected accounts
Google
Not linked
Apple
Not linked
Microsoft
Not linked
Active Sessions
Chrome on macOS
Chrome on Windows
Sign out everywhere else
The whole Security page, third in the Account group, exactly as it looks when you first open it
2
Change your password
Fill in the Current Password, New password and Confirm Password fields. Your new password needs at least 8 characters and must contain at least one lowercase letter, one uppercase letter and one number. A handful of the most common weak passwords (e.g. "Password1") are also rejected outright, even if they meet these rules.
As you type, a green hint appears under the field: Medium strength password from 8 characters, Strong password from 12. The hint only measures length; it doesn't check for uppercase letters or numbers. So even if the screen says "strong", your password will be rejected when you save if it doesn't meet the rules above.
The Save button stays grayed out until your new password is at least 8 characters long and typed the same in both fields. When everything's ready, click Save.
Security
Password and two-factor authentication settings.
Change Password
••••••••••
••••••••••••
Strong password••••••••••••
SaveCancel
The Save and Cancel buttons appear as soon as you start typing in any field
3
Sign in again with your new password
The moment you click Save, your password changes and the message Password changed successfully appears. At the same time, Pumpynotes closes every session on your account, including the one you're using; about 1.5 seconds later you're taken to the sign-in screen.
There's a reason for this: if you're changing your password because you suspect another device, that device is locked out right along with you. Just sign in again with your new password.
Security
Password and two-factor authentication settings.
Change Password
Password changed successfully
About 1.5 seconds after this message, you're taken to the sign-in screen
4
See which devices are signed in to your account
To see which devices have been used to sign in to your account, scroll down to the Active Sessions section at the bottom of the same page. Your phone, your work computer, or a friend's laptop you signed in on once: each one sits on its own row here. Every row shows the browser and operating system, the IP address and the sign-in date.
The device you're using right now is marked with a green This device badge. There's no Sign out button next to it; this list only lets you sign out your other devices.
Active Sessions
Chrome on macOS
Chrome on Windows
Each row shows the device's browser and operating system, not its model
5
Sign out of a device you don't recognize or no longer use
If you spot a device or IP address you don't recognize, or a session from an old computer you no longer use is still there, click Sign out next to that row. Only that session closes and the row disappears from the list; that device can't get into your account again without signing in.
If you're not sure which ones are yours, or don't want to go through them one by one, use the red Sign out everywhere else button under the list. It closes every session except the one on the device you're using, in one go.
Active Sessions
Chrome on macOS
Chrome on Windows
Sign out everywhere else
The red button appears whenever the list has at least one device besides yours
If you've lost your phone or suspect someone else has gotten into your account, change your password first. Signing a device out isn't enough on its own, because anyone who knows your password can simply sign in again. Changing the password closes the sessions on every device anyway, so there's no need to click Sign out everywhere else as well.
Frequently Asked Questions
Why am I signed out right after changing my password?
When your password changes, Pumpynotes closes every session, including the one you're working in. If someone else had gotten into your account, they're locked out too; just sign in again with your new password.
I forgot my password. Do I reset it here?
No. The form on the Security page is for when you're already signed in and know your current password; the current password field is required. If you've forgotten it, use the Forgot your password? link on the sign-in screen and set a new one with the reset link sent to your email. The link is valid for 15 minutes. Resetting your password this way also closes all your sessions.
I sign in with Google. Can I change my password here?
If your account has never had a password, this form won't work and you'll see the warning This account does not have a password set. That's the case if you sign in to Pumpynotes with your Google, Apple or Microsoft account. If you'd still like a password, use the Forgot your password? link on the sign-in screen; the password you set through the reset link in your email is added to your account, and from then on you can use this form too. If you don't want a password, there's nothing to do; just keep signing in with that account.
Why was a password that looked "strong" rejected?
The green hint under the field only counts characters: at 8 it says Medium strength password, at 12 Strong password. The rule applied when you save goes further and also requires at least one uppercase letter, one lowercase letter and one number. That's why a long password made only of lowercase letters can look strong on screen and still be rejected. Use all three kinds together and avoid passwords anyone could guess, like "Password1".
Does signing out a device close its session right away?
Yes. The session is invalidated on the server at that moment, not just removed from the list: Pumpynotes checks on every request whether a session is still valid. If the app is still open on that device, the page doesn't close by itself, but nothing done there is saved anymore, and reloading the page brings up the sign-in screen.
How do I turn on two-factor authentication?
From the Two-Factor Authentication (2FA) section on the same page. Click Start Setup, scan the QR code that appears with an authenticator app, enter the 6-digit code the app generates and click Verify and Enable. From then on, signing in asks for this code as well as your password; the browser where you entered the code is remembered for 30 days. 2FA is also available on every plan, Free included.
Which plans is this page available on?
Changing your password and managing your sessions are available on every plan, Free included. Account security isn't a plan perk.