Skip to main content
← Help center

Your account

Signing in to your account

Kabora has no password for new accounts. The first screen asks for one thing — your email address — with any Google or Apple button underneath it. The proof comes after.

The emailed code

We send you a six-digit code. It lasts 10 minutes, and you get five tries before it stops working — a wrong one tells you how many you have left. Asking for another code cancels the one before, so always use the newest email. If nothing arrives, Send a new code is on the code screen.

It is always email. Kabora does not text sign-in codes.

Your account's one way in

Every account signs in one way, and Kabora asks for that one first: the emailed code, a passkey, or an authenticator app. It is whichever you set up most recently, or the one you picked under Account settings → Sign-in & security → Sign in with. You are only ever asked for one.

  • A passkey. The screen reads Use your passkey and your device asks straight away. Email me a code instead sits under it, for a machine your key is not on.
  • An authenticator app. A small window asks for the app's code. Use a different way, then Email me a code instead, sends you the emailed code. A backup code goes in the same box.
  • The emailed code. The code screen has Use a different way too, which offers your passkey, and a password if your account still has one.

In the Kabora app a passkey works the same way. The app has no authenticator step, so an account that signs in with one gets the emailed code there.

Passkeys

Kabora offers to set one up once: right after the code that makes your account. Not after later sign-ins, and not after Google or Apple. Any time after that, add one under Account settings → Sign-in & security → Passkeys, on kabora.app or in the app, and it becomes your way in. Removing one is on the same screen.

Google and Apple

These sit under the email field on the first screen, where Kabora offers them, so you may see one, both or none. Link or unlink either under Sign-in & security.

What each refusal means

  • "That passkey couldn't be used here. Try another way in." The check failed and Kabora will not say which part — an expired request, a browser answer it could not read, the wrong site. Take its advice and get a code.
  • "That passkey isn't registered here." Kabora has never seen that key: it was made for another site, or it has since been removed from your account. Use a code.
  • "That request expired. Try again." The attempt sat too long. Start it again.
  • "That passkey looks cloned. Sign in another way." Two things answered for one key. Do not ignore this — sign in with a code.
  • "That code didn't match." An authenticator code is only good for about 30 seconds. Ten wrong ones in a day stop the authenticator until the time the message names; Use a different way still works.
  • "That account's email address isn't confirmed with the provider." Confirm it there, or carry on with your email.
  • "Too many attempts." The message says how long to wait — sometimes a number of minutes, sometimes just "less than a minute".
  • "That code has expired. Ask for a new one." Past the 10 minutes. Send a new code is on the same screen.

If your account still has a password

A handful of accounts predate all this and still have one. On the code screen choose Use a different way, then Use your password. From a browser Kabora has not seen before, the right password is followed by an emailed code. You can remove a password under Sign-in & security, and it cannot be set again.

Did this help?Still stuck? Contact support