Security

See every device signed in to your Cooper account, sign out the ones you don't recognize, read your sign-in activity for the last 90 days, and turn your own two-step verification (an email code at every sign-in) on or off.

The Security tab shows where your Cooper account is signed in and what has happened on it recently. You use it to sign out a device you don't recognize, to check a sign-in you weren't expecting, and to turn on two-step verification so that every sign-in also needs a code from your email.

Everything on this tab is about your own account. Nobody else in your workspace, including admins, can see your devices or your sign-in activity, or change your two-step verification.

The Security tab with the Two-step verification card, the Where you're signed in list of devices, and the Recent sign-in activity list
The Security tab. 1: Two-step verification and its On/Off status, 2: Turn on, 3: Where you're signed in, 4: This device, 5: Details and Remove on another device, 6: Recent sign-in activity, 7: Refresh.

Key concepts

TermWhat it means
DeviceOne browser or one Cooper mobile app that has signed in to your account. Chrome and Safari on the same computer are two devices.
This deviceThe browser or app you are using right now. You can't remove it from the list; use Sign out instead.
Sign-in activityA log of sign-ins and security changes on your account, kept for 90 days.
Two-step verificationYour own setting. When it is on, Cooper emails you a 6-digit code every time you sign in, on any device, including when you sign in with Google.
Company two-step verificationA workspace-wide setting an admin turns on. It asks everyone in the workspace for an email code when they sign in with a password. See Company two-step verification and yours.
Unusual sign-in checkCooper's automatic check on every sign-in. When a sign-in looks unusual, Cooper asks for an email code or sends you an alert, even if two-step verification is off.
New sign-in emailAn email Cooper sends when a new device signs in to your account. It has a Secure my account button that signs that device out.

Open the Security tab

  1. Click your name at the bottom of the sidebar.
  2. Click Account settings.
  3. Click the Security tab.

The page address is /auth/profile-settings/security.

Every signed-in user can open this tab. It needs no role permission.

If the tab can't load, it says Could not load your security settings (or the reason from the server) with a Try again button. While the settings are missing, the two-step verification card shows no status and no Turn on or Turn off button, so it never shows the wrong state.

What the Security tab shows

The tab has three cards. On a wide screen, the first two sit on the left and the activity list on the right.

CardWhat it shows
Two-step verificationWhether your own two-step verification is On or Off, and the button to change it.
Where you're signed inEvery device signed in to your account, with the number of devices at the top.
Recent sign-in activitySign-ins and security changes on your account from the last 90 days, newest first.

Under the device list, Cooper notes that locations are approximate and come from the IP address, so a VPN or a mobile network can show a different city.

See where you're signed in

The Where you're signed in card lists every device on your account, the most recently active first. Each row shows:

  • The device name, such as Chrome on macOS or Cooper mobile app on iOS. A phone icon marks the mobile app; a monitor icon marks a browser. A device Cooper can't identify shows as Unknown device.
  • This device next to the browser you are using now.
  • The approximate location, such as "Austin, United States (approx.)", or Location unknown.
  • When it was last used: Active now (used in the last 10 minutes), Last active 3 hours ago and so on, or Not active yet. Cooper updates this at most every 5 minutes while a device is in use.

Click Details on a row to see more:

A device row in Where you're signed in with its Details panel open
A device's details. 1: device name and location, 2: Details, 3: Remove, 4: the details: IP address, location, browser and OS, sign-in times and whether it was confirmed with a code.
DetailWhat it means
IP addressThe internet address of the device's last sign-in, or Unknown.
LocationCity and country from that IP address, marked approximate, or Unknown.
Browser / OSThe browser and operating system, such as "Chrome · macOS 14".
Last sign-inWhen the device last signed in.
First seenWhen the device first signed in.
Confirmed with a codeWhen the device last finished a sign-in with an email code, or No.

Times are shown on your company's clock (the workspace time zone), for example "14 Sep 2026, 3:42 PM CDT".

If the list is empty, it says No devices yet. Each device appears here the next time it signs in. A device that has stayed signed in without signing in again since this list was added appears after its next sign-in.

How Cooper recognizes a device

  • A browser gets a random ID the first time it opens Cooper. The ID is stored in the browser and kept when you sign out, so signing in again from the same browser is the same device.
  • Clearing the browser's site data, or using a private or incognito window, gives the browser a new ID. Cooper then treats it as a new device.
  • The Cooper mobile app is recognized by the app, the operating system and the phone model. It counts as a known device only when it signs in from the same country it was last seen in.
  • Signing out with Sign out does not remove a device from this list. The device keeps its row and appears as last active when you last used it. Remove it if you no longer use it.

Sign out a device you don't recognize

Find the device

In Where you're signed in, find the device. Click Details to check its IP address, location, browser and sign-in times.

Click Remove

Click Remove on the device's row. Remove is not shown on This device.

Confirm

The Sign out this device? window shows the device and its location. Click Sign out device, or Cancel to keep it.

Change your password

If you don't recognize the device, change your password next. See Password.

When you click Sign out device:

  • The device is signed out straight away. Its next request to Cooper is refused and it has to sign in again.
  • Its browser push notifications and mobile app push notifications stop.
  • The device disappears from the list, and Cooper shows "(device name) signed out".
  • Device signed out and removed is added to your sign-in activity.
  • If the device signs in again, it counts as a new device and you get a new sign-in email about it.

Removing a device does not change your password. Anyone who knows your password can still sign in again, so change it when you remove a device you don't recognize.

Sign out every other device

There is no single button to sign out all other devices. Click Remove on each device you want to sign out, then change your password.

Changing your password does not sign other devices out on its own. Remove the devices as well.

Review your sign-in activity

The Recent sign-in activity card lists what happened on your account in the last 90 days, newest first. Activity older than 90 days is deleted automatically.

Each entry shows what happened, the device, its approximate location and IP address (or No device details), and the time on your company's clock. The list shows 20 entries at a time; click Show older activity at the bottom for more. Click Refresh at the top to reload it. The list also refreshes by itself after you remove a device or change two-step verification.

EntryWhat it means
Signed inA sign-in that needed no code.
Signed in with an email codeA sign-in finished with a code from your email.
Sign-in code sentCooper emailed a sign-in code. The sign-in isn't finished until the code is entered.
Wrong sign-in code enteredSomeone entered a wrong code.
Wrong password enteredSomeone tried to sign in to your account with a wrong password.
Device signed out and removedA device was removed from Where you're signed in.
Sign-in reported as not youSomeone used Secure my account in a new sign-in email.
Two-step verification turned onYour two-step verification was switched on.
Two-step verification turned offYour two-step verification was switched off.

Gray tags on an entry say why a code was asked for, or what made a sign-in look unusual:

TagMeaning
New deviceThe sign-in came from a device Cooper hadn't seen on your account.
Company two-step verificationYour workspace requires a code.
Your two-step verificationYour own two-step verification asked for the code.
Unusual sign-in checkCooper asked for a code because the sign-in looked unusual.
New countryA new device signed in from a country your account had never signed in from.
After wrong passwordsA new device signed in after 5 or more wrong passwords in the last hour.
Unusual travelA new device signed in too far from your last sign-in for the time between them.
After a reported sign-inA new device signed in within 7 days of a sign-in being reported as not you.
Device in a different countryA known device signed in from a different country than it was last seen in.

If the list is empty, it says No sign-in activity yet. It is recorded from your next sign-in. If it can't load, it says Could not load sign-in activity with a Try again button.

Turn on two-step verification

Two-step verification adds an email code to every sign-in. Cooper sends the code to your account email address. There is no authenticator app, text message or backup code option; the code always comes by email.

Click Turn on

On the Two-step verification card, click Turn on. Cooper emails you a 6-digit code and shows "Code sent to (your email)".

Find the email

The email's subject is "(code) is your code to turn on two-step verification". The code works for 10 minutes.

Enter the code

Type the 6 digits in the box under Enter the 6-digit code we sent to (your email) to turn two-step verification on. The box accepts digits only.

Click Confirm

Click Confirm. Cooper shows Two-step verification is on, the card status changes to On, and Two-step verification turned on is added to your activity.

Didn't get the email? Wait for Resend in 30s to count down, then click Resend code. A new code replaces the old one. Click Cancel to stop without changing anything.

From your next sign-in, Cooper asks for a code every time, on any device, with a password or with Google. Devices that are already signed in stay signed in.

Turn off two-step verification

Turning two-step verification off also needs a code from your email, not your password. This keeps someone who is signed in on your computer from switching it off, and works for people who sign in with Google and have no password.

  1. On the Two-step verification card, click Turn off.
  2. Open the email "(code) is your code to turn off two-step verification".
  3. Enter the 6-digit code and click Confirm.

Cooper shows Two-step verification is off, the card status changes to Off, and Two-step verification turned off is added to your activity.

With two-step verification off, Cooper still asks for a code when a sign-in looks unusual, and your workspace may still require a code. See Company two-step verification and yours.

If you get a turn-off code you didn't ask for, don't share it. Someone may be signed in to your account: check Where you're signed in and change your password.

Sign in with a code

When a sign-in needs a code, Cooper emails one after you enter your password (or choose Google) and shows a code screen instead of opening the app.

Read the screen

The screen is titled Verify your email when two-step verification asked for the code, or Confirm it's you when the sign-in looked unusual. It names the email address the code went to.

Find the email

The subject is "(code) is your CooperBuild sign-in code". The email shows the device, location and time of the sign-in attempt.

Enter the code

Type or paste the 6 digits into the six boxes. Cooper checks the code as soon as the sixth digit is in, or click Verify & continue.

On the code screen:

  • Didn't get it? shows Resend in with a countdown, then Resend code. The first countdown is 240 seconds; after a resend it is 60 seconds.
  • Change email takes you back to the sign-in form.
  • A wrong code clears the boxes and shows Invalid code. Please try again.

Rules for sign-in codes:

  • A code expires after 10 minutes.
  • Each sign-in allows 5 tries. Wrong codes still count after you click Resend code. After the fifth try, sign in again with your password.
  • Only the newest code works. A resend replaces the earlier code.

The same code check runs when you sign in to Cooper to connect an AI assistant, such as Claude or ChatGPT, through the CooperBuild MCP server.

Company two-step verification and yours

An admin can require two-step verification for the whole workspace. It is the Two-Factor Authentication switch in the Organization Settings card on Settings → Organization (/settings/organizationDetails). Turning it on or off needs edit access to that page.

The workspace setting and your own setting are separate:

  • You can't turn company two-step verification off from the Security tab. Your card shows only your own setting.
  • When the workspace setting is on, the workspace's rule is used. Your own setting adds the code to sign-ins the workspace rule doesn't cover.
  • Company two-step verification doesn't ask for a code when you sign in with Google. Your own two-step verification does.
How you sign inCompany two-step verification onOnly your two-step verification onNeither on
Email and password, in a browserCode every timeCode every timeCode only when the sign-in looks unusual
Email and password, in the mobile appCode every timeCode every timeNo code; an alert email when a new device signs in or the sign-in looks unusual
GoogleCode only if your own setting is onCode every timeNo code; an alert email when a new device signs in or the sign-in looks unusual

Unusual sign-ins

Cooper compares every sign-in with the devices and countries your account has used before.

A sign-in looks unusual when:

  • A device Cooper already knows signs in from a different country than it was last seen in, or
  • A new device signs in and any of these are true:
    • Your account has never signed in from that country.
    • There were 5 or more wrong passwords on your account in the last hour.
    • Your last sign-in was too far away for the time since (more than 500 km away, faster than 900 km/h, within the last 24 hours).
    • A sign-in was reported as not you in the last 7 days.

What happens then:

  • Email and password in a browser: Cooper asks for a code on the Confirm it's you screen. If the code email can't be sent, the sign-in goes ahead and the new sign-in email still tries to reach you.
  • The mobile app or Google: the sign-in goes ahead and Cooper sends you a new sign-in email instead.

New sign-in emails and "This wasn't me"

Cooper emails you, with the subject "Security alert: New sign-in to your CooperBuild account", when:

  • A new device signs in to your account (your first sign-in on record counts), or
  • A sign-in looked unusual but went ahead without a code (the mobile app or Google).

You don't get this email when the sign-in was confirmed with a code, because you already had a code email about it.

The email shows the device, location and time. If it was you, you don't need to do anything. If it wasn't:

Click Secure my account

In the email, click Secure my account. A page titled Wasn't you? opens.

Sign the device out

Click Sign that device out. Nothing happens until you click it, so an email scanner opening the link can't sign a device out. If it was you after all, click It was me — go to sign in.

Change your password

The page says That device is signed out. Click Change my password to reset your password, or Go to sign in.

After you report a sign-in:

  • That device is signed out straight away and removed from your device list.
  • For the next 7 days, any new device that signs in to your account with a password in a browser has to enter an email code.
  • Sign-in reported as not you is added to your activity.

The link works once and for 7 days. An old or used link shows We couldn't use this link with the reason, such as "This link has expired or was already used. Sign in and check Profile settings → Security." You can still remove the device on the Security tab.

Limits and rules

WhatLimit
Sign-in activity kept90 days
Activity shown per page20 entries
Code length6 digits
Code lifetime10 minutes
Tries per code5, counted across resends
Wait before asking for another code30 seconds
Active nowUsed in the last 10 minutes
"Last active" updatedAt most every 5 minutes
"This wasn't me" linkWorks once, for 7 days
Extra checks after a report7 days
Devices per accountNo limit

Permissions

ActionWho can do it
Open the Security tabEvery signed-in user, for their own account
Remove a deviceYou, for your own devices. You can't remove This device.
Turn your two-step verification on or offYou, with a code from your email
See someone else's devices or activityNobody. There is no admin view.
Require two-step verification for the whole workspaceAn admin with edit access to Settings → Organization

When an admin is viewing Cooper as another user, the Security tab refuses to show or change anything and says Exit the user view to manage security settings. Click Exit user in the menu under your name first.

Tips and best practices

  • Turn on two-step verification if you use Cooper on shared or public computers.
  • Check Where you're signed in now and then. Remove old laptops and phones you no longer use.
  • Don't ignore a new sign-in email you don't recognize. Click Secure my account and change your password.
  • Never share a code with anyone. Enter it only on the Cooper sign-in screen or the Security tab.
  • Keep your email account secure. With two-step verification on, your email is the key to your Cooper account.
  • Signing in from a private window or after clearing browser data makes the browser look new, so expect a new sign-in email.

Troubleshooting

For AI agents

There is no CooperBuild MCP tool for this tab. An agent can't list a user's devices, read their sign-in activity, sign a device out, or turn two-step verification on or off. The generic db_* tools can't reach these records either: user accounts are blocked for everyone, and device and sign-in records are not open to regular users.

Rules for agents:

  • Never say or imply that you have changed a user's devices, sessions or two-step verification. Send the user to Account settings → Security (/auth/profile-settings/security).
  • Never ask a user for a sign-in code, a two-step verification code or a password, and never repeat one a user pastes. Codes give access to the account.
  • If a user reports a sign-in they don't recognize, tell them to remove the device on the Security tab (or click Secure my account in the new sign-in email) and change their password.
  • Company two-step verification is a workspace setting. A workspace admin changes it in Settings → Organization. The update_tenant tool can change it, but only for Cooper super admins; don't use it on a user's behalf.

Use this page to explain errors a user sees:

MessageWhat to tell the user
"Verification code has expired. Please sign in again."The code is over 10 minutes old. Sign in again.
"Too many incorrect codes. Please sign in again."All 5 tries are used. Sign in again with the password.
"A code was just sent. Please wait a few seconds before asking again."Wait 30 seconds before asking for another code.
"This is the device you are using now. Use Sign out instead."The current device can't be removed. Use Sign out.
"This link has expired or was already used."Remove the device on the Security tab instead.
"Exit the user view to manage security settings"The user is in an admin's user view. Exit it first.
  • Password — change your password after removing a device you don't recognize.
  • My Details — your name, photo and contact details.
  • Notifications — the sounds Cooper makes.
  • Connections — accounts you have connected to Cooper.

Last updated on

On this page