My Account - Security
Displays security settings, where you can reset your password.
To navigate to your Security settings, click on your Account user icon () in the top right corner of your Onshape window. This opens a dropdown menu. Click My account.
Click Security in the list on the left side of the page. This brings you to your Onshape Security settings. Change your Onshape system password, and also enable (or disable) two-factor authentication:
If you have forgotten your password and need it reset, proceed to the Onshape sign in page and click the "Forgot your password?" link to access a page on which you can request a password reset link via email:
- Expand the menu under your user name and select My account:
- Select the Security tab.
- Click Change password and enter the old password, the new password, and re-enter the new password.
The list of guidelines leads you through creating a password. Each requirement is marked when your password fulfills the requirement.
- Click Update password.
Onshape highly recommends taking advantage of our two-factor authentication functionality. Two-factor authentication (2FA) allows you to configure your Onshape account to require more than a single password to sign in. Using one password to sign into a website makes you more susceptible to security threats because one piece of static information may be easy to guess or acquire. With 2FA, a second piece of information is required, and that second piece of information is generated dynamically during the sign in process, and may be different each time you sign in.
We highly recommend you use 2FA for Onshape and for all websites you use that support it.
How it works
Download a two-factor authentication app (like Google Authenticator) to your phone and set it up with Onshape through the Onshape user interface. This enables the app to generate a one-time code that Onshape is able to recognize. Once you enable 2FA in Onshape, Onshape will prompt you for the 2FA code after you sign in with your password.
You can allow the 2FA mechanism to remember the devices on which you sign in so that once you use 2FA authentication to sign in to Onshape from a specific device, you won't need a 2FA code to sign in on that device for 30 days.
- Download a two-factor authentication app to your device.
- Sign in to your Onshape account.
- In the menu under your username, select My account.
- In the list on the left side of the page, click Security.
- To the right of Two-factor Authentication, click Enable.
- Click Set up two-factor authentication.
- Confirm password.
- Click OK.
Google Authenticator is one example.
Continuing from the instructions above:
- Use the Authenticator app on your device to scan the QR code presented in the Onshape user interface.
- Enter either the six-digit code that the 2FA app generates or the code supplied by Onshape.
- Click Enable.
- When the recovery codes are displayed, copy them to a safe place; you need access to them in the event you do not have your phone or the authentication app.
- Click OK.
Once registration is complete, the phone app will list a code for each registration you create. It is these codes that you enter into Onshape when presented with the 2FA sign in page.
If you are not able to use the QR code, click the enter this text code link provided in the Onshape interface to obtain a code.
Onshape provides you with 5 active recovery codes at a time. Keep these codes in a place accessible to you separate from your device or the authentication app.
Onshape will not be able to help you should you delete the app or lose your phone.
You can generate these Recovery codes at any time through the Onshape interface, but only the most recently generated series are active at any one time. Once you use a code it is no longer valid. When you generate a new list of codes, all previous codes (used or unused) become invalid.
When two-factor authentication is enabled, Onshape prompts you for a code upon sign in:
- After you enter the password to your Onshape account, you are prompted for the authentication code.
- Open the two-factor authentication app on your device to view the code; enter the code in Onshape.
- Click Verify.
In the event that you don't have access to the app, click the Enter a two-factor recovery code link to enter one of your current recovery codes.
You may disable (and re-enable) two-factor authentication at any time.
- On the Security tab of the User Profile page in Onshape click Manage, and then Disable:
- Confirm password.
- Click OK.
Should you need to replace a device on which you have 2FA enabled for Onshape:
- Before replacing the device, disable 2FA through the Onshape interface.
- Enable 2FA once the new device is online.
Note that Onshape doesn't support the Replace 2FA option.