← Back to Wiki
Using Outpost

Account Security: Two-Factor, Password Recovery & Deleting Your Account

Your Outpost account lives on one instance, so account security is between you and whoever runs that server. There is no central company to appeal to, which makes the recovery paths worth understanding before you need them.

Two-factor authentication

Open user settings and go to Security. Two methods are available and you can use both.

Authenticator app (TOTP)

Scan the QR code with any authenticator app and enter a code to confirm. You are then shown backup codes, once.

Save those codes. Each one works a single time, and they are what gets you in when your phone is lost, reset or in another room. Settings shows how many you have left, and you can regenerate the set with your password, which invalidates the old ones.

Passkeys and security keys

Register a passkey from the same panel. That covers a hardware key, your phone, or the passkey support built into your operating system and browser. You can register more than one, which is the sensible setup: one that lives on your keyring and one that lives in your laptop.

Turning two-factor off asks for your password again.

Password recovery on a self-hosted server

There are two paths, and which one exists depends on the instance:

If you run the instance, decide which of these you rely on before somebody needs it. An instance with no mail configured and an owner who is on holiday has no recovery path at all.

Encryption keys are not covered by any of this

Worth repeating here because it surprises people. A password reset does not restore your encrypted direct messages. The server never had that key, so it cannot give it back. The recovery code you saved when you turned encryption on is the only route, and it is separate from your backup codes.

Deleting your account

User settings, at the bottom. Deleting asks for your password, asks you to type your username, and asks for a two-factor code if you have one enabled. It is immediate and it cannot be undone.

Removed: your account, your passkeys, your roles, your friendships, your reactions, your read state, your avatar, and any invite links you created. An invite is a live join credential, so one left behind would keep admitting new members on the authority of an account that no longer exists.

Kept: your messages, which stay in place and render as Deleted User. Deleting them would punch holes through every conversation you took part in, including other people's replies and quotes. Attachments on those messages stay for the same reason, and moderation log entries about you survive so the audit trail stays intact.

If you want your messages gone, delete them before you delete the account.

The instance owner cannot delete their own account

There is no ownership-transfer mechanism, so an owner deleting themselves would strand the instance with nobody able to reach instance settings or reset a password, and the claim code is consumed at first registration and never reissued. The owner's route is to shut the instance down instead.