Skip to content

Devices and sessions

There are four ways into your account, and one place that shows you every device currently holding a session. Password is the obvious way in, but on a device where typing a long password is miserable, the QR and magic link options are usually faster.

The Publiz sign-in page with social buttons, an email and password form, and links for the magic link and QR options.The Publiz sign-in page with social buttons, an email and password form, and links for the magic link and QR options.

Enter the email you signed up with and your password. If you forget it, Forgot password? sends a reset link to that address.

If you’ve turned on two-factor authentication, you’ll be asked for a six-digit code from your authenticator app after the password. Lost your phone? One of the backup codes you saved when you set 2FA up works in the same box, and each one works once.

The buttons at the top of the sign-in page hand you over to that provider, and you come back signed in. Which buttons appear depends on what’s enabled for your Publiz account, so don’t worry if you see fewer than someone else.

If the provider doesn’t tell us your name, Publiz asks for it once right after you land, then never brings it up again.

Email me a sign-in link sends a link to your address that signs you in when you open it. No password involved.

The magic link page asking for an email address.The magic link page asking for an email address.

The link works once and expires after 15 minutes. Asking for a new one cancels the old one straight away, so if you request twice, only the second email works.

Open it on the same device you asked from and the sign-in completes on the spot. Open it somewhere else and you may be asked to confirm, because a link that signs in any device that receives it is a link worth stealing. On an account with two-factor turned on, the link stands in for the second factor only in the browser that asked for it — anywhere else you’ll still be asked for your code.

This is the one to use on a TV, a shared machine, or anywhere typing a password feels like a bad idea. You need a phone or laptop where you’re already signed in to Publiz.

  1. On the new device, pick Sign in with a QR code on the sign-in page. A code appears, along with a short text code underneath it.

    The QR sign-in screen showing a QR code, the matching short code, and a countdown.The QR sign-in screen showing a QR code, the matching short code, and a countdown.
  2. On the device you’re already signed in on, scan the QR. If the camera isn’t cooperating, open the link shown under Can’t scan? instead and type the short code. There’s also a scan button on the Devices tab itself.

  3. Check the code matches, then approve. The approval screen tells you which browser and IP address asked, so you can tell your own sign-in apart from someone else’s.

    The approval screen showing the requesting browser and IP address with an Approve button.The approval screen showing the requesting browser and IP address with an Approve button.
  4. The new device signs itself in. You don’t have to do anything else there, the screen changes on its own.

The code expires after five minutes and you can ask for a fresh one from the same screen. While you wait, the screen tells you where things stand: waiting, scanned, approved, denied, or expired. Once approved, the new device has about a minute to finish signing itself in before the code is thrown away.

The QR image only ever carries that short code, never anything that would sign someone in, so a photo of the screen is not worth anything on its own.

Every sign-in becomes a session you can see and end. Open Settings, then the Devices tab.

The Devices tab listing active sessions with their browser, sign-in method, IP address, and last activity.The Devices tab listing active sessions with their browser, sign-in method, IP address, and last activity.

Each card shows:

  • The browser and operating system, like Chrome on macOS
  • How that session signed in — Password, Connected account, Sign-in link, or QR code
  • This device on the one you’re using right now
  • The IP address
  • When it was last active, and when it signed in

One detail that surprises people about QR sign-in: the device recorded is the one that signed in, not the one that approved it. So look for the TV or the borrowed laptop in this list, not your phone.

Sign out on any card ends that session immediately. If that device has Publiz open, it signs itself out within seconds rather than waiting for someone to reload.

Sign out everywhere else ends every session but the one you’re using. That’s the button to reach for if you think someone else has access.

Your own card’s button is deliberately disabled. To sign out of the device you’re on, use Sign out in the sidebar as usual.

When a session starts on a device we haven’t seen before, Publiz emails you. It lists the device, the IP address, how it signed in, and when, with a link straight back to this page.

It’s sent for every way of signing in, not just QR. Two cases deliberately don’t send one:

  • Your first device, since the welcome email already covers that.
  • A browser and operating system you already have another session on. So signing in again from the same Chrome on the same Mac, even on a different network, is quiet. A genuinely new browser or a new machine is not.

If one arrives and it wasn’t you, sign that device out from this page and change your password.