Warmerlydocs
Billing & account

How do I sign in, change my password or email, and secure my account?

You can sign in to app.warmerly.com with your email and password, or with Google or Microsoft. Your name, password and login email are in Settings > Profile. This page covers only what exists today; anything not listed here is not a setting you can change.

How do I sign in?

  • Email and password: enter them on the sign-in page and click Sign in. The address must be verified first. If it is not, you see "Please verify your email address before signing in" with Resend verification email. Verification links last 24 hours.
  • Google or Microsoft: use the matching button on the sign-in page. Your Google photo is used as your avatar automatically, and you can upload a different one.

After too many wrong attempts, sign-in is blocked for a short while and you are asked to try again later. This applies per email address and per network.

A signed-in session lasts up to 30 days on that browser. Signing out ends it on that browser.

How do I change my password?

  1. Open Settings > Profile.
  2. In the password section, enter your Current password, your New password and Confirm new password.
  3. Click Update password.

The new password must be at least 8 characters. It is also checked against lists of passwords known to be leaked; only a short fragment of a fingerprint of it is ever sent for the check, never the password itself. A leaked password is refused.

Changing your password signs out every other session (other browsers, and the Android app) but keeps the one you are using. That is the standard advice after a suspected compromise, and it works.

If you signed up with Google or Microsoft you may not have a Warmerly password at all. The password form needs an existing one to confirm it is you.

I forgot my password

On the sign-in page, click Forgot password? under the password field (or go to app.warmerly.com/forgot-password), enter your email address and click Send reset link. The page always shows the same message, whether or not that address has an account, so it cannot be used to find out who is registered.

If the address has an account, we email a Reset password link. It expires after 24 hours and works once. Asking for a new link cancels the previous one. Open the link, enter a New password and Confirm new password, and click Set new password. The same rules apply as when you change it in Settings: at least 8 characters, and a password found in known leaks is refused.

Resetting your password signs you out everywhere, including other browsers and the Android app. You are then sent to the sign-in page to use the new password. If the link says it has expired or was already used, request a new one from the same page. Too many requests in a short time are refused for a while, so wait a minute and try again.

If you use Google or Microsoft sign-in, use that button instead. Warmi cannot reset a password for you.

How do I change my login email?

  1. Open Settings > Profile and find Change email.
  2. Enter the New email and your Current password, then click Send code.
  3. Check the new address's inbox for a Verification code, enter it and click Confirm.

The code is valid for 15 minutes and you get a limited number of tries. After that, request a new code. You will see specific messages if the email is already used by another account, the password is wrong, or the code is wrong or expired.

Your login email is separate from your display name and does not change anything else on your account, such as your mailboxes or billing.

Is two-factor authentication available?

Not at the moment. There is no two-factor option in Settings > Profile. What protects your account today: a long, unique password, sign-in through a provider that you have secured with its own two-step verification (Google or Microsoft), and the session and audit features below.

What other security features are there?

  • Sessions are revocable. Each sign-in is a session on Warmerly's side. Changing your password and signing out end sessions properly, so a copied cookie stops working.
  • API keys are shown once and stored only in a scrambled form. Manage them under Settings > Platform API keys (an Agency plan feature). See How do I use Warmerly with an API?.
  • Connected apps: see and revoke every AI app connected to your workspace under Settings > Connected apps. See Connected AI apps.
  • Webhooks are under Settings > Webhooks. See Webhooks.
  • Audit log: Settings > Audit log lists recent workspace activity. See Audit log.
  • Roles: only owners can change billing or delete a workspace. See Team members and roles.
  • Mailbox passwords and tokens are deleted immediately when you disconnect a mailbox.

Common problems

"Invalid email or password." Check the address and try again. If you signed up with Google or Microsoft, use that button.

"This account has been suspended." See My account is suspended.

"I never got the verification email." Check spam, then click Resend verification email. You can only ask again after about a minute.

"I think someone else has access." Change your password now (that signs out other sessions), revoke unknown apps and API keys, review the Audit log and email support@warmerly.com.

Something unclear or out of date? Ask Warmi in the chat, or email support@warmerly.com.