Part of the ChordexBio ecosystem

Account recovery
without the email.

Authling lets you reset your password using a one-time code from your phone — no waiting on emails, no inbox required.

Step 1 — Identity
Enter your email on the recovery page
Step 2 — Your app generates a code
Open your authenticator app
refreshes in —s
Step 3 — Reset password
Code verified. Set your new password.
Identity confirmed
password reset complete
Works with
Google Authenticator iOS · Android · Free
Authy iOS · Android · Desktop · Free
1Password iOS · Android · Desktop
Microsoft Authenticator iOS · Android · Free
Bitwarden iOS · Android · Desktop · Free
OTP Auth iOS · Paid
andOTP Android · Free · Open Source
Aegis Authenticator Android · Free · Open Source
Google Authenticator iOS · Android · Free
Authy iOS · Android · Desktop · Free
1Password iOS · Android · Desktop
Microsoft Authenticator iOS · Android · Free
Bitwarden iOS · Android · Desktop · Free
OTP Auth iOS · Paid
andOTP Android · Free · Open Source
Aegis Authenticator Android · Free · Open Source
RFC 6238 · Any TOTP app

Three steps. No inbox needed.

01

You enroll once

While logged in, visit the security settings and scan a QR code with Google Authenticator, Authy, or any TOTP app. Takes 60 seconds.

02

Your app holds the key

Your phone generates a fresh 6-digit code every 30 seconds using the same algorithm as your account — no internet required on the phone side.

03

Code in, password out

When you need recovery, enter your email, type the current 6-digit code, and set a new password. Done — no email sent, no waiting.

0 emails used per recovery
30s code refresh interval
15m recovery session window

Email recovery has a problem.
We fixed it.

The old way

Email-based reset

Password reset emails can land in spam, get delayed, or hit a daily quota limit. If reset links fail to reach your inbox, you're locked out until emails arrive — even if it's urgent. Worse, a compromised inbox means a compromised account.

Authling

TOTP-based recovery

Your phone generates codes offline using a shared cryptographic secret. No email is ever sent. No sending limit applies. Works at 3am, works with no signal on your laptop, works instantly. The code proves you physically control the enrolled device.

Pick your situation.

1

Log in to your account

You need to be signed in first. If you're already locked out, jump to the "Recover my account" tab.

2

Go to your security settings

Find the "Set up authenticator" or 2FA link in your account or profile settings. It takes you to an Authling enrollment page.

3

Scan the QR code

Open your authenticator app, tap + or "Add account", then point your camera at the QR code or manually input the cryptographic key. No internet needed on your phone for this step.

4

Enter the first code to confirm

Type the 6-digit code shown in your app and submit. This confirms the link is working correctly. You're done.

1

Go to the recovery page

Click "Forgot password?" on your ChordexBio platform's login page. This takes you to the Authling recovery flow.

2

Enter your email address

Type the email linked to your account. If you've enrolled an authenticator, the page will advance to the next step.

3

Open your authenticator app and enter the code

Find ChordexBio account in your app's list. Type the current 6-digit code. Codes refresh every 30 seconds — if one just expired, wait for the next.

4

Set your new password

Once your code is verified, you'll be taken straight to a password reset form. You have 15 minutes to complete this step.

No authenticator enrolled yet? You'll need to contact the platform's support team for manual verification, or use the email recovery option if available. We recommend enrolling before you need it.

1

Log in and go to security settings

Navigate to the Authling enrollment page from your account settings while you're signed in.

2

To replace — click "Set up new authenticator"

This generates a new QR code. Scan it with your new app. Your old enrollment is replaced only after you confirm with a valid code from the new setup.

3

To remove — enter your current code and confirm removal

You must enter a valid code from your existing authenticator to prove you still control it. This prevents someone else from removing your protection.

Built into
ChordexBio. Not bolted on.

Authling is not a third-party service. It runs entirely within the ChordexBio platform infrastructure. Your TOTP secret never leaves the server it's stored on, and it's encrypted at rest. No external API, no third-party dashboard, no data sharing.

If you're seeing an Authling page on a ChordexBio domain, it is legitimate. You can verify the domain in your browser's address bar.

AES-256 encrypted at rest TOTP secrets are never stored in plaintext
Single-use recovery tokens Expire in 15 minutes · consumed on first use
Rate-limited on every step 5 attempts / 5 min · blocks brute-force
RFC 6238 standard TOTP Same protocol used by Google, GitHub, Stripe

Common questions.

Is this page legitimate? Why does it look different from ChordexBio?
+
Yes. Authling is ChordexBio's dedicated security subdomain (authling.chordexbio.com). Keeping security flows on their own subdomain is standard practice — it isolates the authentication surface and makes the URL easy to verify. Check your browser's address bar: if it shows a chordexbio.com domain with a valid padlock, you are in the right place.
What if I lost or replaced my phone?
+
If you used Authy, your codes are backed up to Authy's cloud — install Authy on your new device and restore from backup. For Google Authenticator with the sync feature enabled, sign in to the same Google account on your new device. If you have no backup, contact ChordexBio support for manual identity verification.
Why don't I get an email when I recover?
+
That's intentional. Authling is designed to work without sending any email at all. The 6-digit code is the proof of identity — it's generated from a cryptographic secret that only your device and the server share. No email needed, no sending limit applies.
Can someone guess my 6-digit code?
+
Practically, no. There are 1,000,000 possible codes and each is valid for only 30 seconds. After 5 wrong attempts from the same IP address, Authling blocks further attempts for 5 minutes. Guessing would require ~83 hours of unblocked attempts — the code will have cycled through millions of values before then.
Does Authling work on all ChordexBio platforms?
+
Authling is the shared recovery backbone deployed across ChordexBio's ecosystem of platforms. Each platform maintains its own user database, but the enrollment and recovery flows are identical everywhere. Once you're familiar with the process on one platform, it works the same on all others.
I see "account not found." What do I do?
+
This message appears either when the email isn't registered on this platform, or when the account exists but doesn't have an authenticator enrolled. Both cases show the same message to prevent exposing which accounts exist. Double-check you're on the right platform's recovery page, and confirm you've enrolled an authenticator from the settings page while logged in.