Profile & security
Update your profile, change your password, and set up two-factor authentication.
Profile & security
Your account settings live under your avatar in the top-right corner of MediSync. Click it and choose Account to open them.
Update your profile
Under Account → Profile you can edit:
- Display name — what teammates and clients see.
- Phone number — used for SMS two-factor codes (optional).
- Avatar — upload a square image (at least 256 × 256 px).
Changes save as soon as you click outside each field.
Change your password
- Open Account → Security.
- Click Change password.
- Enter your current password, then the new password twice.
- Click Save. You'll stay signed in on this device and be signed out everywhere else.
If you've forgotten your current password, sign out and follow the Forgot your password? flow on the sign-in page — see Sign in.
Two-factor authentication (2FA)
2FA adds a second step after your password: a short code generated by an authenticator app (or sent to your email if you don't have one).
Set it up
- Open Account → Security.
- Click Enable two-factor authentication.
- Scan the QR code with an authenticator app such as Google Authenticator, 1Password, or Authy, or enter the key manually.
- Enter the 6-digit code your app shows to confirm the pairing.
- MediSync displays recovery codes — download or write them down and store them somewhere safe. Each code works once and lets you sign in if you lose your authenticator.
Sign in with 2FA
After you enter your password, MediSync asks for a 6-digit code. Open your authenticator app and type the code for MediSync. Codes rotate every 30 seconds — if one is about to expire, wait for the next.
Turn 2FA off or reset the device
- Turn it off. In Account → Security, click Disable two-factor authentication and enter your password to confirm. Only do this on devices you trust.
- Lost your authenticator. Use one of the recovery codes saved during setup. If you've lost those too, your clinic admin can reset 2FA on your account.
Active sessions
Account → Security → Active sessions lists every browser and device currently signed into your account. For each session you can see the last activity timestamp, IP address, and user agent. Click Revoke next to a session to sign that device out.
Use Revoke all other sessions after changing your password or if you suspect your account has been used without you.
API access tokens
If your clinic integrates MediSync with another tool, Account → Security → Access tokens lets you create short-lived tokens for API use. Each token shows its scope, last-used time, and expiry. Create one, copy it immediately (it's only shown once), and revoke it when the integration no longer needs it.
In-app help: account_access_token, account_active_sessions,
account_email_verified, account_session_expires_in.