Keep your Practor account safe
Practor signs you in with an emailed link, so add a second factor under Profile, Security, and make recovery codes before you need them.
Signing in to Practor starts with your email address. Practor sends a one-time link, and opening it lets you in. There is no password to forget, and none to be stolen.
The trade is that your mailbox now matters a great deal. Your records, your invoices and your appointments sit behind whoever can read it. Profile → Security is where you make that harder.
Ask for a code as well
Turn on a second factor and signing in wants a code on top of the link. Two kinds can be switched on.
| Method | What it is |
|---|---|
| Authenticator app | An app on your phone makes the code. It works with no signal, and Practor marks it Recommended |
| Text message | The code arrives by SMS. Marked Weaker, because whoever takes over your number receives it |
The app is the safer of the two, and Practor says why on the row itself: a text gets sent to whoever controls the number.
Pick the app and you get a square to scan, then a box for the number it shows you.
Your phone is gone and Practor wants a code
At the prompt, choose Use a different method, then Use a recovery code. The box changes shape, because a recovery code runs to eight characters with a dash in the middle.
That only helps if you made the codes first, so make them now while you can. The Security page has them under Recovery codes, and Practor offers a copy or a download before asking you to confirm you've saved them. Somewhere that isn't the phone.
Each one works once, and the card shows how many are left. If you've run out, your practice can't help and neither can a reset: contact support to get back in.
Practor asks for a code every single time
Tick Trust this device for 30 days at the prompt and it stops asking on that computer or phone for a month.
Leave it unticked on anything you share or don't own. A trusted device is one that no longer needs your code, which is the whole point and also the whole risk.
Trusted devices on the Security page lists every one you've ticked. Anything on it you don't recognise can be revoked there, and that device asks for a code again.