A little paranoia is just good housekeeping
Keep the keys to the collection in good hands.
A collection can reveal what you own, what it is worth, and where it lives. KolleK gives you practical ways to protect access without turning account setup into an evening activity.
Scan in your authenticator
Or enter this setup key manually:
Recovery codes
Add a second factor
A stolen password stops being enough.
Turn on two-factor authentication and one leaked password no longer opens the door. Keep the recovery codes somewhere safe, ideally not in the same place as the phone that generates the codes.
Authenticator app
Time-based codes from any TOTP app. Scan the QR once and you are set.
Recovery codes
One-time codes for when the phone is lost. Kept off-device, on purpose.
Breached-password check
New passwords are checked against known breaches before they are accepted.
Sign in without another password
Let your inbox do the vouching.
Magic links let you sign in from your email when that is more convenient. Less password wrangling, fewer “which one did I use?” moments.
Sign in to KolleK
no-reply{{ Str::lower(config('app.name')) }}.app · to jamie@…
Here is your one-time sign-in link. It expires in 15 minutes and can only be used once.
Sign in to KolleKDidn’t request this? You can safely ignore it, nothing changes until the link is used.
Know when something looks off
The first hint should come from us.
KolleK emails you about failed sign-ins, new devices, changed IP addresses, and API-key changes. The first time you learn about a strange login should not be from a stranger.
Chrome on Windows · Denver, US · verified with 2FA.
Location changed from Portland to Denver, US.
Key “export-script” created with read-only scope.
3 failed attempts on your account, then rate-limited.
Make good choices easy
Every control in one place.
Security settings put passwords, two-factor authentication, recovery codes, API keys, and account protection together. The controls are there before you need them.
Password
Last changed 4 months ago · checked against breaches
Two-factor authentication
Authenticator app · 6 recovery codes remaining
Magic-link sign-in
Sign in with a one-time email link
Security alert emails
New logins, IP changes, and API-key events
API keys
1 active key · read-only scope
Turn on the protection while it is quiet.
Two-factor, recovery codes, magic links, and actionable alerts, set them once from one settings page.
KolleK might not be for you (yet) if…
You require SSO, hardware security keys, or a full enterprise identity platform.
You need end-to-end encryption.
Choose KolleK when…
You want strong everyday account protection without turning setup into a project.
You want two-factor authentication, recovery codes, magic links, and actionable security alerts.
Encryption at rest is covered on the data ownership page; this is not end-to-end encryption. The feature status page has the boring-but-important details.