Skip to content

Authentication

TextFlow uses secure email and password authentication to protect your account and data.

Your TextFlow account is protected by:

  • Strong password requirements (minimum 8 characters)
  • Rate limiting (5 login attempts per 15 minutes)
  • Secure password encryption (passwords never stored in plain text)
  • Session management (automatic logout after 24 hours of inactivity)
  • Email-based password reset (with 15-minute expiration codes)

If you’re logging in for the first time, see the First Login Guide for a complete walkthrough.

  1. Use a strong, unique password

    • Minimum 8 characters
    • Mix of uppercase, lowercase, numbers, and special characters
    • Never reuse passwords from other services
  2. Change your password regularly

    • Every 90 days recommended
    • Immediately if you suspect compromise
  3. Never share your credentials

    • Administrators will never ask for your password
    • Each user should have their own account
  4. Log out on shared computers

    • Prevents unauthorized access to your session
  5. Use a password manager

    • Generate and store complex passwords securely
    • Examples: 1Password, LastPass, Bitwarden

TextFlow enforces rate limits to prevent brute-force attacks:

ActionLimitWindow
Login Attempts5 attempts15 minutes
Password Reset Requests3 attempts1 hour
Password Reset Verification5 attempts15 minutes

If you exceed these limits, wait for the time window to expire before trying again.

  • Session Duration: 24 hours of inactivity
  • Automatic Logout: After session expires
  • Session Storage: Secure, encrypted cookies

If you’re locked out due to too many login attempts:

  1. Wait 15 minutes for the rate limit to reset
  2. Contact your administrator if urgent

Use the Password Reset flow to regain access.

If you’re logged in and remember your current password, use Change Password.


Your account security is important. Follow these best practices to keep your TextFlow account safe.