If you’ve lost access to your passkey or 2FA, you can recover it directly from the Login page (not from the desktop app).
💡 Lost a device but still signed in on another one (for example, your phone is gone but your laptop still works)? You likely don’t need recovery at all:
If your passkey is saved in iCloud Keychain or Google Password Manager, it syncs to your new device through your Apple or Google account — install Bron and sign in with it directly.
To restore signing on the new device, request trust from it and approve the request from the device where you still have signing — it takes minutes and there is no security delay. See Managing Trusted Devices.
Use the recovery described below only if you can’t sign in on any device.
1. Start recovery
On the Login screen, select Lost access → enter your email → complete the captcha and press Continue:
You’ll receive an email with a secure link to continue the recovery process from no-reply@bron.org
2. Follow the link
Open the email from Bron and click Recover access.
If you already have passkeys, Bron will first show a "Before you continue" screen listing where your passkeys are saved (for example, iCloud Keychain or Google Password Manager) and when they were created. Check those places first — signing in with an existing passkey is faster than recovery. If you find one, click Sign in with passkey; otherwise press Continue recovery.
The next steps depend on what you have set up. In every case, all verification happens at the start: you confirm your email, present what you have (a 2FA code, FaceScan, or guardian codes), and create your new passkey right away. The passkey stays inactive inside the recovery request while the security delay runs and activates automatically when the delay ends. The delay itself is a cancellation window: your current passkeys keep working, and signing in with one of them cancels the recovery.
You are not locked into the first method offered: the recovery screen lets you switch between Recover with FaceScan, Recover with Guardians, and Recover with Extended delay. Switching cancels your previous recovery request and starts a new one, and the security delay for each method is shown before you start.
How long is the security delay?
The length depends on two things: whether any of your workspaces has ever moved $100 or more, and what you can present besides your email.
No workspaces at all (and no membership in the last 30 days): access is restored instantly after you confirm your email.
Your workspaces never moved $100 or more: 2 days. A face verification, or a valid 2FA code when you have no working FaceScan, restores access instantly.
A workspace has moved $100 or more: 2 days after you verify yourself with FaceScan or with recovery codes from 2 guardians. If neither is available, the delay is 30 days, or 14 days with a valid 2FA code.
Two things can raise the delay one step (2 days → 7 days → 30 days, never above 30 days):
A 2FA marked as lost. If you have 2FA set up, you are asked to enter the code or mark it as lost before recovery continues.
A working FaceScan you skip, when nothing else verifies the request. Recovery codes from 2 guardians count as full verification and remove this step.
If you are in several workspaces, recovery follows the rules of the most protected one. Leaving or being removed from a workspace does not reset this for 30 days: recovery still follows that workspace’s rules and its members are notified.
Case 1: No existing accounts
If you don’t have any existing accounts created with this email, and you haven’t been a member of any workspace in the last 30 days, you’ll be able to restore access immediately and create a new passkey.
Case 2: Recovering with FaceScan
If FaceScan recovery is set up on your account (and its 30-day security delay after setup has passed), Bron will offer it automatically:
Complete the face verification — agree to the use of iProov, allow camera access, and scan your face.
Create your new passkey.
If any of your workspaces has ever moved $100 or more, a 2-day security delay runs; your access is restored automatically when it ends. Otherwise access is restored right after the verification, no delay.
⚠️ If you have 2FA set up, you’ll be asked to enter the code or mark it as lost before continuing. A lost 2FA extends the delay from 2 to 7 days.
On the FaceScan screen you can always switch to recovery with guardians or recovery without them.
Case 3: Recovering with guardians
Guardian recovery lets you regain access to your Bron account by collecting recovery codes from people you previously designated as guardians. You need codes from at least 2 guardians to complete the process.
Start from the Bron login screen and select the recovery option. You’ll be asked to verify your identity by confirming your email address before the process begins.
To start, confirm your email address. You’ll receive a confirmation link by email, click it to proceed. You and your guardians will be notified that recovery has started. Guardians can log in with their passkeys and see their recovery codes right away, so you can collect the codes immediately, there is nothing to wait for first.
If you close the recovery window at any point, you’ll receive an email with a link back to your recovery request. Click the link to return to where you left off and continue entering your codes when you’re ready.
Collect and Enter Recovery Codes
To complete recovery:
Collect recovery codes from 2 of your guardians
Return to your recovery request via the email link or the app
Enter the codes in Bron
Create your new passkey
Always confirm directly with your guardians before using their codes. Once the codes are accepted and your new passkey is created, a 2-day security delay starts (7 days if your 2FA is set up but marked as lost). When it ends, your passkey activates and your access is restored automatically.
⚠️ Recovery codes can come only from guardians who accepted their invite more than 30 days ago. A recovery request cannot expire while the delay is running: it stays valid for the whole security delay plus 15 days. Once your part is done, you no longer need to watch the clock.
Case 4: Recovering with extended delay
This is the do-it-alone lane. You can choose it deliberately — press Recover with Extended delay on the recovery screen, even when FaceScan or Guardians are available — and it is also where recovery lands when you have neither FaceScan nor guardian codes to present. The flow works the same way, with one key difference: the security delay is extended. If any of your workspaces has ever moved $100 or more, the delay is 30 days, cut to 14 days if you confirm your 2FA code. Otherwise it is 2 to 30 days, as described above.
The rest of the flow is identical. You’ll receive a confirmation link by email to initiate the request, and if you close the recovery window at any point, you can return to it using the link in your email or by clicking "Lost access" on the login screen. Once the delay ends, your new passkey activates and access is restored automatically, no guardian codes required.
Browser Compatibility:
If you are unable to create a new passkey in your browser, you may need to remove the existing passkey associated with the site. Depending on your browser, this can be done in:
Chrome: Chrome settings - Autofill and Passwords - Google Password Manager
Safari: Your device’s Passwords app
3. Security note
During the delay, all your current passkeys remain active. If you sign in with your existing passkey while a recovery request is active, the recovery will be automatically cancelled. Members of your workspaces can also see the request and cancel it if it wasn’t started by you.
If you encounter any issues during the recovery process, contact our support team by email at support@bron.org










