WASync · Developers
Changelog

19 September 2026

Passkeys, two-step sign-in and a security page for the developer console.

Passkeys, two-step sign-in and a security page for the developer console

New. The developer console at developers.wasync.app now offers three ways to sign in — password, a 6-digit email code, or a passkey (Face ID, Touch ID, Windows Hello or a hardware key) — and a mandatory second step for accounts that hold API keys: a passkey (which satisfies both steps at once), an authenticator app, or one of ten single-use recovery codes.

New accounts set up the second step right after creating the account. Existing accounts get a 14-day heads-up before it becomes mandatory; account admins have no grace period. A new Security page lists your signed-in devices (revoke any of them), your last 12 months of account activity, and lets you manage your passkeys, authenticator app and recovery codes.

Sensitive actions — creating or revoking an API key, rotating a webhook secret, deleting a connection, closing a workspace, or changing your two-step setup — now ask you to reconfirm your second step if it has been more than a few minutes since you last did. Repeated failed sign-in attempts bring up a Cloudflare Turnstile challenge, and ten wrong passwords in 15 minutes apply a temporary 15-minute lock to the account (password sign-in only — a passkey or email code always still gets you in).

See Developer console sign-in for the full picture.

On this page