Account and billing
Two-factor sign-in and audit log
Blipit signs you in with a magic link, Google or GitHub, and there is never a password. Two-factor adds a code from an authenticator app on top. Owners and admins can also read an audit log of who did what.
1Turn on two-factor
Settings, Two-factor sign-in: scan the QR code (or enter the key by hand), type the 6-digit code, and save the 10 one-time backup codes shown once. Codes are standard TOTP (6 digits, 30 seconds), and each code and each backup code works once. Turning it off or making new backup codes asks for a current code.
2Signing in with it
After the link, Google or GitHub step you land on the code page with a 5-minute window and 5 attempts per 5 minutes. A correct code starts the normal 30-day session.
3Require it for the workspace
Settings, Workspace: an owner who has two-factor on can require it for everyone. Members without it are sent to set-up before they can use the workspace, and nobody in it can turn their own two-factor off. Only an owner with two-factor on can change the rule in either direction.
4Audit log
Audit log in the sidebar, filters by activity, person and date, 50 rows a page. Recorded: sign-ins and failed second factors, two-factor on and off and new backup codes, the workspace requirement, Terms acceptance, project creation and secret key rotation, invites, revoked invites, role changes, removals and leaving, plan checkout, plan changes and billing portal visits, AI credit purchases and AI fix runs, alert channels added and removed, monitors created and deleted. Each row has actor, target, detail, IP and user agent.
Good to know
- Audit rows are deleted after 365 days.
- The TOTP secret is stored encrypted and backup codes as keyed hashes; a copy of the database does not reveal them.
Stuck? Email support@blipit.io. Keys and the exact DSN for each project are under API keys in app.blipit.io.

Sign in