Skip to main content
If you think an account has been compromised, the priority is to cut off the intruder’s existing access before you investigate. This page is the sequence to follow.
Terminating sessions is the step that ends live access. Changing a password, suspending a user or deleting an API key each closes a different door — and suspending a user does not log them out. Work through the steps in order rather than picking one.

Signs of a compromise

Investigate if you see any of these:
  • A security notification email for something nobody performed — a password change, a new passkey, recovery codes viewed, an email address change request, or a new user added
  • A session in Settings → Sessions from a location, IP address, device or browser you don’t recognise
  • A user, role or status you didn’t expect on the Users page, or a Last Login that doesn’t match what that person did
  • An API key in Settings → API keys that nobody remembers creating
  • Unexplained credit consumption in the credit usage log under Billing & Plans
QuivaWorks does not keep an account audit log. The signals above are the record you have, so capture screenshots of anything unusual before you start terminating things — sessions disappear from the list once they are terminated.

If your own account is compromised

1

Change your password

Open Settings → Password and authentication and click Change password. You’ll be asked to confirm your identity with two-factor authentication first.This terminates every other session on your account and leaves your current one signed in. You’ll receive a confirmation email.
2

If you're locked out, reset instead

If the intruder has already changed your password, click Forgot Password on the login screen and enter your email address, then click Reset Password. Follow the link in the email you receive — it’s valid for 2 days.Resetting while signed out terminates every session on the account, including the intruder’s.
3

Check no sessions remain

Open Settings → Sessions. Only your current session — the one with the green Your session pill — should be left. Click Terminate sessions to clear anything else.
4

Delete your API keys

Open Settings → API keys and delete every key you can’t account for. A key keeps working regardless of your password, so this step is not optional.Reissue replacements afterwards and update whatever was using them. See API keys.
5

Check your authentication methods

Back in Settings → Password and authentication, open Manage under Passkey and remove any passkey you didn’t register. Check whether an authenticator app you don’t recognise is enrolled.
6

Issue new recovery codes

Click Get New in the Recovery codes section. This invalidates the old set, including any copy the intruder took.
7

Enable MFA if it wasn't on

A passkey or an authenticator app stops a stolen password being enough on its own. See Authentication.
A session token copied with Copy token stays valid until that session expires or is terminated. If a token may have leaked, terminating the session it came from is the only thing that revokes it — changing your password terminates other sessions, so it covers this too.

If another user’s account is compromised

Root and admin users can act on other members of the account. Open Users in the sidebar — depending on your account it sits at the top level or under More — and use the dot menu on the user’s row.
1

Logout — first

Logout revokes that user’s tokens and ends every session they have open. This is the step that stops an intruder who is currently signed in.
2

Suspend — second

Suspend blocks the account from signing in again. Do it after Logout, not instead of it: suspending on its own leaves any live session working until it expires.
3

Delete their API keys

Keys are managed by their owner in Settings → API keys, so have the user delete theirs once you’ve spoken to them. A key issued by a compromised user keeps working after Logout and Suspend.Treat an account-scoped key as the most urgent of these — see API keys.
4

Issue new recovery codes

Use Issue new recovery codes in the same dot menu to invalidate the existing set.
5

Have them reset their password

They start it themselves with Forgot Password on the login screen. There is no admin-initiated password reset.
6

Delete the user if they should no longer have access

Delete removes them from the account entirely.

If an API key is exposed

  1. Delete the key in Settings → API keys — this revokes it immediately
  2. Issue a replacement, and consider making it a restricted key limited to the endpoints it actually needs
  3. Deploy the replacement everywhere the old key was used
  4. Review your own application logs — they are the only record of what the key did
The full sequence is in API keys.

After containment

Establish what the compromised identity could see. A user’s role determines this, so start from the roles reference and the resources granted to that user.An account-scoped API key or a root or admin session should be assumed to have reached everything in the account.
Check the Users page for accounts added during the incident, roles that were elevated, and anyone who no longer needs access.
  • Enable MFA on every privileged account
  • Reduce the number of root and admin users
  • Replace broad API keys with restricted ones
  • Delete keys and users that exist only out of habit

Getting help

Help Centre

Contact us through the help centre for anything you can’t resolve from the steps above, or to report a security vulnerability.

Sessions

Terminate sessions and log other users out

Authentication

Passwords, MFA and recovery codes

API Keys

Scopes, restricted keys and revocation

Security Overview

Platform and account security