Skip to main content

Confirm Your Identity for Sensitive Actions

BillManager asks for fresh proof of identity before some sensitive account actions. This check protects an account when another person has an open session.

Actions That Need Confirmation​

BillManager asks for confirmation when you:

  • Link a sign-in provider to your account.
  • Add a passkey.
  • Replace your recovery codes.
  • Delete a passwordless account.

A password-based account deletion asks for the current password in the deletion form.

Confirmation Methods​

BillManager checks these methods in order:

OrderAccount conditionConfirmation method
1The account has a password.Enter the current password.
2The passwordless account has a linked identity from the enabled generic OIDC provider.Sign in again with that identity.
3Neither earlier condition applies.Enter the code sent to the verified email address.

The OIDC provider must support a fresh sign-in request and return a signed authentication time. This method does not need an email service.

Email confirmation needs a verified email address and a working email service. Ask the deployment administrator to check the email setup if the code does not arrive.

Complete the Action​

  1. Start the sensitive action.
  2. Complete the Confirm your identity prompt.
  3. BillManager continues the original action after successful confirmation.

Each confirmation is valid for five minutes. It works one time and only for the action that requested it.

A password or email change cancels an unused confirmation. Start the action again to get a new prompt.