2026-09-19

Two-step verification, passkeys, and a security log

  • Two-step verification with an authenticator app and recovery codes. Settings → Security.
  • Passkeys in your web browser. Face ID, Touch ID, Windows Hello, or a security key.
  • Workspace admins can require two-step verification for everyone.
  • Deleting an account or issuing an API key now asks for your code again.
  • Security log in workspace settings: who signed in, changed a role, issued a key, or connected a tool. Append-only, hash-chained, CSV export, retention from 1 to 7 years.
  • Export all your data as one JSON file from Settings.
  • Agent browser: scripts run in an isolated world, per-site "stay signed in", and touching the page pauses the agent.
  • Local agent work mode runs in a macOS sandbox.
  • Desktop app rejects modified or downgraded builds.
  • Security fixes to session handling and dependency updates.

How each of these works: markhub.ai/security