Account and DNS credentials
An account has an owner. The owner can invite admins. DNS provider secrets and billing stay with the owner.
Sign-in
You can sign up with email and a password, or with Google or Apple. Email sign-up uses a verification link. The password is stored as a hash. A reset link lasts one hour. Signing in with Google or Apple stores the verified email those providers share.
Each person can turn on an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, or Authy). Sign-in then asks for a 6-digit code or one unused recovery code. Recovery codes are shown once. There is no skip. If you lose the phone and the codes, support verifies it is you before changing MFA.
The owner can require MFA for the account. Owner and admin authenticators are separate. Someone who has not enrolled cannot manage sites until they do, when the requirement is on.
People
The owner invites admins. An invite lasts 7 days. Admins can manage sites, DNS, WAF, and alerts. They cannot manage billing or membership. The owner can revoke a member.
Your referral link lives on the account page. The offer is in the billing doc.
DNS credentials
Only the account owner can connect, replace, or remove DNS credentials. Status reads “Connected — credentials on file (hidden)” or “Not connected.” The saved token is not shown back to you.
Credentials are stored encrypted on the account. Remove deletes our copy. Revoking access at Cloudflare or GoDaddy is a separate step, and the page says so.