Password, passkeys & two-factor
Change your password, add or remove passkeys, and turn on two-step verification for your WAQAF account.
This page is about keeping your own sign-in safe: changing your password, adding a passkey so you can sign in with your device's fingerprint or face, and turning on two-step verification so a password alone isn't enough to get in. WAQAF looks after real money and donor records, so it's worth spending a few minutes here when you first join — and again whenever you change your phone or laptop.
Who can do this. Everything on this page is about your own account, so there's no role requirement — any signed-in member can manage their own password, passkeys, and two-step verification. It does not affect anyone else's account, and your role has no bearing on it. (What your organisation allows as sign-in methods is a separate, organisation-wide setting; see Login & security policy.)
Where to find it. Open the Account menu and choose Security (Account → Security). Everything below lives on that one page, each in its own card.
Change your password
The Your password card is where you set a new password. Pick something long and unique that you don't use anywhere else.
Open Account → Security
From the Account menu choose Security, and find the Your password card at the top.
Enter your current and new password
Type your Current password, then your New password. As you type, WAQAF shows whether the new password meets each requirement: at least 8 characters, upper and lowercase letters, a number, and a special character. You can use the eye icon to check what you've typed, or select Generate to have WAQAF create a strong password for you.
Save
Select Save. The button stays disabled until the new password meets every requirement. Once it's saved you'll see a confirmation.
Changing your password signs you out everywhere else. As a security precaution, every other browser and device that was signed in to your account is logged out, so you'll need to sign in again on those. The browser you're using right now stays signed in.
No password yet? If you joined using Google or Apple and never set a password, the card shows a Set password button instead. Selecting it emails you a link to choose one — open the email and follow the link. After that, the card switches to the change-password form described above.
Add or remove a passkey
A passkey lets you sign in with your device's fingerprint, face, or screen lock instead of typing a password. It's both faster and harder to phish, so it's a good thing to add. The Passkeys card lists the passkeys on your account and lets you add, rename, or remove them.
Select Add passkey
On the Passkeys card, select Add passkey. Your browser or device takes over and prompts you to confirm — usually with your fingerprint, face, or device PIN. Follow that prompt to finish creating the passkey.
Give it a recognisable name
Straight after it's created, WAQAF asks you to name the passkey. Choose something that tells you which device it's on — for example Work laptop or My phone — so you can recognise it later. Select Save.
Rename or remove later
Each passkey in the list has a pencil icon to rename it and a bin icon to remove it. Removing a passkey only deletes it from WAQAF; it doesn't change anything stored on your device.
If you don't see a Passkeys card at all, passkeys aren't switched on for your deployment — that's not a fault. You can still sign in with your password or the other methods your organisation allows.
A passkey is tied to the device you created it on. If that device is your only way in and you lose it, you could be locked out — so keep at least one other way to sign in (a password, or a passkey on a second device).
Turn on two-step verification
Two-step verification (shown in WAQAF as Two-factor authentication) adds a second check after your password: a six-digit, one-time code from an authenticator app on your phone. Even if someone learns your password, they still can't get in without that code. The Two-factor authentication card walks you through it.
You'll need an authenticator app on your phone first — for example Google Authenticator, Microsoft Authenticator, or any app that generates one-time codes. You also need a password on your account: if you signed in with Google or Apple and haven't set one, the card asks you to set a password first before you can enable two-step verification.
Select Enable two-factor authentication
On the card, select Enable two-factor authentication. WAQAF first asks you to verify with your password — type it in and select Continue. This confirms it's really you changing a security setting.
Scan the QR code with your authenticator app
A dialog shows a QR code. Open your authenticator app, add a new account, and scan the code. If you can't scan it, the app will accept the secret shown beneath the code, typed in manually instead.
Enter the six-digit code to confirm
Your authenticator app now shows a six-digit code that changes every few seconds. Type the current code into the field and select Verify. WAQAF checks it and switches two-step verification on — from now on you'll be asked for a code each time you sign in.
Keep your authenticator app and phone safe, and never share the codes — they're the second key to an account that can move real money. If you replace your phone, turn two-step verification off on the old device and on again on the new one (see below), or you may find yourself unable to produce a code.
Turn it off
When two-step verification is on, the card shows a green tick and a Disable two-factor authentication button. Selecting it asks for your password again before switching the protection off. Only turn it off if you're moving to a new device or no longer want the extra step.
Other things on this page
The Security page also has two more cards worth knowing about:
- Connected accounts — shows whether your WAQAF account is linked to Google or Apple, and lets you connect one so you can sign in that way. (Which methods actually work at the sign-in page is set by your organisation's policy.)
- Active sessions — lists every browser and device currently signed in to your account, with the current one marked. If you see a session you don't recognise, select the X beside it to sign it out. Signing out your current session logs you out of WAQAF here.
Your organisation may limit some of this. Each organisation chooses which sign-in methods it allows. If, for example, your organisation has switched off password sign-in, the Set password option won't help you get in — you'll use the method your organisation does allow. See Login & security policy for how that's decided.
See also
Your profile
Update your name, language, and the rest of your personal details.
Signing in
The everyday ways to get into your dashboard, including two-step verification at sign-in.
Login & security policy
How your organisation chooses which sign-in methods are allowed.
Notification preferences
Choose which emails and alerts WAQAF sends you.
