Lymeno
← All updates

Security

Lymeno now supports two-factor authentication and API tokens

Protect sign-in with an authenticator app, and automate your workflows with workspace API tokens.

Two-factor authentication

Turn on Two-factor authentication under Profile & security. After you confirm your password, scan the QR code with an authenticator app or enter the setup key, and then enter the 6-digit code to finish.

You receive 10 backup codes, each usable once, for when your authenticator app is not available. Choosing New backup codes replaces all existing codes. When you sign in, you can trust a device for 30 days.

API tokens

Workspace owners and admins can create API tokens under Settings → API tokens. Each token has:

  • An access level: Read only, or Read and write, which can do everything an admin can except manage API tokens.
  • An expiration: 30 days, 90 days (the default), 1 year, or never.

The token is shown only once. Send it in the Authorization: Bearer header. API tokens cannot create or revoke other tokens, and every change made with a token is recorded in the audit log under the token’s name.

To limit what an agent can do inside the database as well, read Give every agent its own expiring database role.

Create the first database for your agents

Sign up and create an API token to begin.