Account and data
Account security and two-factor login
Protect your Clientwharf account with a strong password and two-factor authentication, and learn how client sign-in works.
Last updated
On this page
Why it matters
Your workspace holds your clients' files and conversations. A few minutes spent on account security protects them as well as you. We recommend that every team member turns on two-factor authentication.
Passwords
- Passwords must be at least 10 characters long. A longer passphrase that you do not use anywhere else is best.
- A password manager makes it easy to use a unique password for Clientwharf.
- Team members can also sign in with Email me a sign-in link instead of typing a password. Once two-factor authentication is on, sign in with your password and code instead; magic links are turned off for that account.
Forgot your password
- Go to forgot password and enter your email address.
- Open the reset email and choose a new password. The link works once and expires after one hour.
When you reset your password, Clientwharf signs you out of your other sessions. If you did not ask for a reset, you can ignore the email and your password stays the same.
Two-factor authentication (2FA)
Two-factor authentication adds a second step when you sign in: a six-digit code from an authenticator app on your phone. Even if someone learns your password, they cannot sign in without that code.
Turn on 2FA
- Open Account at
/app/account. - Under Two-factor authentication, select Set up two-factor and confirm your password.
- Scan the QR code with an authenticator app. Most common authenticator apps work, including those built into password managers.
- Enter the six-digit code from the app to confirm.
- Save your backup codes somewhere safe, such as your password manager. Each backup code works once.
From then on, Clientwharf asks for a code from your app when you sign in. If you run low on backup codes, select Create new codes.
Lost your phone
Sign in with one of your backup codes instead of an app code, then set up 2FA again on your new device. If you have lost both your device and your backup codes, email support@clientwharf.com from your account's email address. We will verify your identity before making any change, which can take some time. This is deliberate, to protect your account.
Turn off 2FA
You can select Turn off under Two-factor authentication on your account page. We recommend keeping it on.
Sessions
Sessions stay signed in for up to 30 days of normal use. Always sign out on shared or public computers. Resetting your password signs you out everywhere else.
Under Active sessions on your account page you can see where you are signed in. Select Sign out next to a session, or Sign out other devices to end every session except the one you are using.
How your clients sign in
Client contacts do not have passwords. They sign in with a magic link: a single-use link sent to their email address that expires after 15 minutes. Their security depends on their email account, so encourage clients to protect their email with two-factor authentication too.
Magic links are only sent to addresses that have been invited. Requests for unknown addresses get the same on-screen response but no email.
Suspicious activity
If you see activity you do not recognize, or you think someone else has access to your account:
- Reset your password.
- Turn on two-factor authentication if it is off.
- Check Active sessions on your account page and select Sign out other devices.
- Check your team at
/app/teamand remove anyone who should not be there. - Email security@clientwharf.com with what you noticed.
To report a vulnerability in Clientwharf itself, see our security page.