Skip to content
Airsockfly

Account

Security settings

Passkeys (signing in without a password), turning 2FA on in three steps (QR code, manual key, backup codes), turning 2FA off, the active session list and logging other devices out.

What this is for

On this page you look after the safety of your account.

You can add a second login step, check which devices you are logged in on, and log out the ones you no longer use.

Who it is for

For every logged-in customer.

What you see

The page is called "Settings and security". The subtitle: "Manage your account, security and preferences. Your data is safe with us.".

The cards on the page:

Account access

"Look after the safety of your account." Here you will find the "Change password" button, the "Email address" row and the "Passkeys" section.

Passkeys

The description reads: "A passkey replaces your password: you sign in with a fingerprint, a face scan or your device passcode. The key never leaves the device, so it cannot be phished.". Next to it is the "Add passkey" button.

Below is the list of your keys. Each row shows the name (or "Passkey" when it has none), a "Backed up" or "This device only" badge and the date: "Added 14/09/2026". Every key has "Rename" and "Delete" buttons.

When you have no keys yet, you will see the sentence "You have no passkeys yet.".

If your browser does not support passkeys, instead of the button you will see a box: "This browser does not support passkeys. Sign in with your password or use a newer browser.".

Two-step verification (2FA)

The badge says "On" or "Off".

When it is off: "Add a second login step — a code from an app on your phone." and the "Turn on 2FA" button. When it is on: "At login you enter a code from your authenticator app." and the "Turn off 2FA" and "New backup codes" buttons.

If you are a platform administrator and reach this page from the /admin panel, you will see an orange box at the top: "The admin panel requires two-factor authentication" with a "Go to 2FA" link. Administrator accounts must have 2FA on.

Active sessions

"Here you can see the devices you are logged in on." Each row is one device. You see the name (or "Unknown device"), "Signed in: 12/09/2026", "Last active: 14/09/2026" and "IP 83.11.…". The current device carries a "Current session" badge.

Buttons: "Log out" on each row and "Log out other devices" under the list.

Notifications

Two switches: "Price alerts by e-mail" and "Inspiration and promotions". We describe them in a separate article.

Travel preferences

"You change your language, currency and departure airport in your profile." with an "Edit profile" button.

Privacy and data

"Data export, saved travellers and account deletion (GDPR)." with a "Manage privacy" button.

Account deletion

"Before deleting you can check which data will be removed." with a "Delete account" button.

Step by step

Turning 2FA on — three steps

The wizard walks you through it. Above every screen you see "Step 1 of 3", "Step 2 of 3" and "Step 3 of 3", so you always know how much is left.

First install an authenticator app on your phone. It can be Google Authenticator, 1Password, Authy or Microsoft Authenticator. Such an app shows a new six-digit code every 30 seconds.

Step 1 of 3 — Confirm with your password

  1. Click "Turn on 2FA".
  2. An Account password field appears. Type your password. That is proof it really is you. Errors: "Enter your current password" or "The current password is incorrect.".
  3. Click "Generate secret". You will see "Secret generated — finish the setup with a code from the app".

Step 2 of 3 — Connect your authenticator app

The screen offers three ways to the same result. Pick one.

QR code — a large square picture (over 200 pixels, black patterns on white so the camera catches it without zooming in). Open the app and scan it with the camera.

Key to type manually — a string of letters and digits shown in groups of four, for example GEZD GNBV GY3T QOJQ. Use it when you cannot scan the code (for example you are setting 2FA up on the same phone). The spaces are only for readability — apps ignore them. The "Copy key" button puts the key on the clipboard and says so: "Key copied to clipboard".

Address to paste manually — the full otpauth://… address. Password managers (1Password, Bitwarden) understand it as a whole. Next to it there is an "Open in authenticator app" link that opens your installed app straight away.

Then, at the bottom of the same screen:

  1. The app will show six digits. Type them into the Code from the app field. You can also paste the code — we keep only the digits, so "123 456" works the same as "123456". Error: "Enter the six-digit code from your app".
  2. Click "Confirm and turn on".

Important: without this step two-step verification will not be turned on. The screen says so: "At the end type the six-digit code from your app — without it 2FA stays off.".

Step 3 of 3 — Save your backup codes

Only now, when 2FA is really on, do we show the backup codes. You will see a green message "Two-factor authentication is on" and a list of codes under the heading "Backup codes — save them now".

There are three ways to keep them:

  • "Download .txt file" — saves the file airsockfly-backup-codes.txt on your device. The file is built in the browser; the codes are not sent anywhere.
  • "Copy codes" — paste them into a password manager.
  • Writing them down from the screen onto paper.

At the end tick "I have saved the backup codes somewhere safe" and click "Done". Without the tick the wizard will not close and you will see "Please confirm that you saved the backup codes.".

We show the codes only once. We do not keep them in readable form, so they cannot be looked up later — you can only generate new ones.

Adding a passkey

A passkey is a secret remembered by your device (phone, laptop, hardware key) that confirms you are you. Instead of typing a password, you touch the sensor or look at the camera.

  1. Click "Add passkey".
  2. The device will ask how you want to confirm your identity — a fingerprint, a face scan or your screen lock code. Confirm.
  3. You will see the message "Passkey added." and the key will appear on the list.

Important: you can add a key only if you signed in recently (within the last 15 minutes). It is the same reason we ask for your password when you change it: adding a key creates a new route into the account, so an old, forgotten session must not be able to do it. If more time has passed you will see "This action needs a fresh sign-in" — sign out, sign in again and try once more.

Renaming a key

  1. Click "Rename" next to the key.
  2. Type a name you will recognise ("Anna's phone", "Work laptop").
  3. Click "Save". You will see "Passkey renamed.".

The name is only for you — it unlocks nothing and does not change how safe the key is.

Deleting a key

Click "Delete" next to the key. You will see "Passkey deleted.".

Once deleted, that key no longer signs you in. Your password and two-step verification keep working — deleting a key does not lock you out.

New backup codes

  1. Click "New backup codes".
  2. Type your account password.
  3. You will see "New backup codes generated" and the list — with the same "Download .txt file" and "Copy codes" buttons.
  4. Click "Codes saved" to close the list.

Note: new codes cancel all the previous ones.

Turning 2FA off

Removing 2FA needs two proofs — the password alone is not enough. If somebody sat down at your unlocked computer and knew the password, they could otherwise take the lock off your account.

  1. Click "Turn off 2FA".
  2. Type your Account password.
  3. Type the Code from your app or a backup code — six digits from the authenticator app, or one of your backup codes in the xxxxx-xxxxx format. Error: "Enter the six-digit code from your app or a backup code in the xxxxx-xxxxx format".
  4. Click "Turn off 2FA".
  5. After it is off, login no longer needs a code, and all trusted devices are removed.

If you use a backup code, it is used up in the process — it will not work a second time.

Logging devices out

Click "Log out" next to a row — you will see "Session logged out". Click "Log out other devices" — you will see "Other devices logged out". You will stay logged in only here.

What happens next

Once 2FA is on we will ask for the app code at every login. You can tick "Remember this device for 30 days" so you do not enter it every time on your own phone.

The session list refreshes when you open the page. If it cannot be read you will see "The device list could not be read. Refresh the page or log in again.".

Frequent questions

What is a QR code? A square black-and-white picture. The app reads it with the camera and remembers your account.

I lost my backup codes. Go to "New backup codes", confirm with your password and save the new list. The old ones stop working.

I cannot scan the QR code — I am setting 2FA up on the same phone. Use the "Key to type manually" field and type or copy the key into your app. You can also click "Open in authenticator app" — the phone opens the installed app with the details filled in.

I no longer have the phone with the app and I want to turn 2FA off. In the "Code from your app or a backup code" step enter one of your backup codes. If you have no codes either, write to us through the contact form.

Do the backup codes leave my computer when I download them? No. The .txt file is built in the browser from the codes already on your screen — nothing extra is sent to the server.

I see a device I do not recognise. Click "Log out" next to that row, then change your password. It is also worth turning 2FA on.

Why am I asked for my password at every 2FA operation? Because these are sensitive operations. The password proves that you are the one at the screen, not someone who sat down at your unlocked computer.

How is a passkey different from a password? Passwords have to be remembered and can be phished — you only need to type one into a fake page. A passkey never leaves your device and works only on the real Airsockfly site, so there is nothing to phish.

Does a passkey replace two-step verification? In practice, yes: to sign in with one you need your device AND you have to confirm your identity (fingerprint, face, screen lock). That is why signing in with a passkey does not also ask for an app code. You can leave two-step verification on — it covers signing in with a password.

I lost the phone with my passkey. Sign in with your password on another device, go to "Settings and security" and delete the lost phone's key. It is worth logging its session out in the "Active sessions" card as well.

I added a key on my phone — will it work on my laptop? It depends on the badge. "Backed up" means your password manager (for example the iCloud or Google keychain) syncs the key between your devices. "This device only" means the key lives solely where it was created — add a separate one on other hardware.

I cannot see the "Add passkey" button. Your browser does not support passkeys. Update it or use your password.

How many backup codes do I get? A short list of codes in the xxxxx-xxxxx format. Each works only once, so save them all.