# Settings

Your account, your security, and anything you have connected to it.

## Profile

Your name and email. The name is what appears in the dashboard; the email is how you sign in and where receipts go.

## Password & security

Change your password, and turn on **two-factor authentication**.

Two-factor is worth the two minutes. Your Laabam.site account can publish pages on your domain and holds your customers' enquiries — a password alone is thinner protection than that deserves. You get recovery codes when you turn it on. Save them somewhere that is not your browser; they are the way back in if you lose your phone, and they are shown once.

## Session

Where you are signed in. Sign out everywhere if you have used a shared computer or think someone else has your password.

## AI connections

Assistants you have connected — ChatGPT, Claude, anything else speaking MCP. Full explanation: [Using Laabam.site from ChatGPT](/guide/mcp).

### Reading the list

Each connection shows what it was granted:

| Chip | Means |
|---|---|
| **Read only** | Can look at your account. Cannot change anything. |
| **Can propose** | Can send you finished websites, which wait for your approval. |
| **Reads code** | Can read your existing pages, so it can match your design. Paid plans only. |
| **Signed in** | Connected by signing in through the assistant, rather than by pasting a token. |

You also see when it connected and when it was last used. **A connection that is months old and never used is worth revoking** — there is no cost to removing one and adding it again.

### Waiting for you

Website proposals from an assistant. Each shows what it is, which assistant sent it, and two buttons.

**Review code** first. It shows every file, the full source as text, and a preview of the page. Scripts do not run in that preview on purpose — a page able to tell it was being reviewed could show you something harmless and publish something else.

**Publish it** puts the site at a public address. That click is the publish; there is no step after it. **Reject** deletes the proposal.

### Revoking

**Revoke** ends access on the next request. No delay, no cache.

It does not touch anything the assistant helped you build — your websites and enquiries are yours and stay exactly as they are.

### Creating a connection by hand

You can also generate a token to paste into an assistant that cannot sign in through a browser. The token is shown **once**. There is no way for us to show it again, including for support — that is the point of storing only its hash. Lost it? Revoke and make another.

## What a connection can never see

- **Your visitors' phone numbers.** Removed before anything leaves Laabam.site.
- Your uploaded images.
- Your password.

## Deleting your account

Contact us. We will not do it from a button, because "delete everything, irreversibly" deserves a human on both ends. Download your code first — **Download .zip** on each project page.
