Account and Security

Your voxelbench.com account: how to sign in, protect it with two-factor authentication, follow its sign-ins, choose the emails you receive, manage tokens and connectors, and delete it, with what then disappears and what stays.

Your Settings

Settings (Profile & settings in the dashboard menu) has five tabs:

TabWhat you do there
AccountSee your account ID, change your profile picture (JPG or PNG, 2 MB at most), delete your account
ProfileYour public profile: username, display name, bio, who can see it, social links, and which servers it shows
SecurityTwo-factor authentication, password, API tokens and connectors, activity log
SubscriptionYour plan (see Plans & Limits)
NotificationsSign-in alerts, the emails you receive, your personal Discord webhook

Creating an Account and Signing In

There are two ways to have an account:

  • Email and password. Create an account with a Username (3 to 30 letters, digits, underscores or hyphens, used in your profile address), an optional Display Name, your Email and a Password of at least 8 characters with an uppercase letter, a lowercase letter and a digit. voxelbench.com sends a verification link, valid 24 hours: you can sign in once you have opened it. Forgot password? on the sign-in page sends a reset link, valid one hour.
  • Discord or Google. The sign-in page has a button for each. The first sign-in creates the account, with the email address the provider gives; it counts as verified when the provider says it is. Such an account has no password: it always signs in through that provider. If an account already uses the same email address with another way of signing in, the site refuses the sign-in: use the way you signed up with.

Discord and Google are the only providers you can sign in with. The social accounts you link in Profile (Discord, GitHub, Twitter/X, YouTube) are shown on your public profile; they do not sign you in.

A verified email address is also needed to link a server, and to publish a report or share it by link.

Two-Factor Authentication

Two-factor authentication (2FA) asks, at every sign-in, for a 6-digit code that an authenticator app computes, such as Authy, Google Authenticator or Microsoft Authenticator.

To turn it on, go to Security and click Enable 2FA:

  1. Enter your password, if your account has one, and click Continue.
  2. Scan the QR code with your app, or type the key shown under it.
  3. Type the 6-digit Verification code the app shows, then click Enable.
  4. Save the 10 backup codes displayed. Each one works once, in place of an app code, if you lose your phone.

At sign-in, after your email and password, or once Discord or Google has sent you back to voxelbench.com, type the app's code, or a backup code, in the field shown. Tick Trust this device for 30 days to skip the code on this browser for 30 days, whichever way you sign in. An account keeps at most 10 trusted devices; beyond that, the one unused for the longest time is forgotten. Changing your password forgets them all.

Later, Security offers Regenerate for new backup codes and Disable to turn 2FA off; both ask for a code, and for your password if your account has one. The code is also asked when you change your password or delete your account.

The code belongs to your account, not to one way of signing in: an account that signs in with Discord or Google, or that has both a password and Discord, is asked for it in the same way, and a trusted device spares it in the same way. After Discord or Google, the code must be typed within 5 minutes; past that, or after 5 wrong codes, start the sign-in again.

Password

Security โ†’ Password โ†’ Change asks for your current password, the new one twice, and your 2FA code if it is on. Once changed, every session of your account is closed, this one included, the trusted devices are forgotten, and an email tells you the password changed. Sign in again with the new password.

Sign-in History and Alerts

Security โ†’ Activity Log lists the recent security events of your account: successful and failed sign-ins, two-factor steps, password changes and resets, trusted devices, backup codes, and servers linked or unlinked, each with its date, IP address and browser. Filter it by category to find an event. Events are kept 90 days, then deleted.

In the Notifications tab, Login notifications, on by default, emails you when your account is signed in from a new device: a browser and network it has not been signed in from in the last 30 days. The sign-in history used to recognise devices is kept 30 days. The email gives the device, the browser, the system and the IP address. If you do not recognise it, change your password at once.

Emails You Receive

Notifications โ†’ Email notifications has one switch per kind of email:

KindBy default
Monitoring alerts: threshold breaches on your monitored serversOn
Server events: status changes from your event alert rulesOn
Certification updates: status, expiry and contestation of certifications (hosting providers)On
Report moderation: one of your reports flagged or removed by a moderatorOn
Leaderboard overtake: a report dethrones yours inside the top 4 of the leaderboardOn
Blog newsletter: a new article on the VoxelBench blogOff, unless you ticked the box when you created your account, or turn it on here

The first five are about your own servers and reports, which is why they start on; you can turn any of them off. The newsletter is marketing: it is only sent after you said yes. A monitoring alert also needs the email channel ticked on its rule (see Metric Alert Rules).

Security emails are always sent and cannot be turned off: address verification, password reset or change, two-factor authentication turned on or off, account suspension. The new-device email is the exception: it follows the Login notifications switch above.

Unsubscribing. Every email you can turn off carries its own unsubscribe link. It opens a page where Unsubscribe now confirms: opening the link alone changes nothing. Mail apps that offer a one-click unsubscribe button use the same mechanism. You can change your mind at any time in Notifications.

If your account is older than the newsletter consent, an email asked you to confirm it: without an answer, the newsletter stops.

Discord. The same tab takes a personal Discord webhook: paste its URL, click Save, then choose which of the kinds above to mirror to Discord, independently of email. Discord is off for every kind until you choose. Test sends a test message; Remove webhook stops them all.

API Tokens and Connectors

Security โ†’ API tokens creates, lists and revokes the tokens your scripts use, and lists the connectors you authorized, for Claude for instance, which you revoke from the same list. Everything is in API and Tokens and Connect Claude to Your Account. Tokens and connectors can never delete anything, manage your tokens, change where notifications are sent, or touch your billing or your account: those stay in your hands (see What Stays in Your Hands).

Deleting Your Account

Account โ†’ Danger Zone โ†’ Delete Account. To confirm, type your account's email address, then your password if your account has one, and the code of your authenticator app if 2FA is on (a backup code does not work here), and click Delete my account. It is permanent.

What happens, in this order:

  1. Your subscription is cancelled first. If it cannot be cancelled, nothing is deleted and the site says so: try again a moment later.
  2. Your reports are detached, not deleted. Your benchmark reports and unit test results stay, but no longer belong to any account. A public report stays on the leaderboard, shown as Anonymous; an unlisted one still opens from its link, and a private one stays private. They expire as usual.
  3. Your account is deleted, and your sessions end on every device.

What disappears with the account:

  • your profile and settings, your two-factor setup, trusted devices and sign-in history;
  • your linked servers, and with them their monitoring data, events, alert rules and alert history, auto-bench targets, performance profiles and their summaries, and memory reports;
  • your server groups, notifications, webhooks and Discord webhook, and the Microsoft accounts you lent to auto-bench;
  • your API tokens and connector authorizations, which stop working at once.

Why reports stay. A public report is a measurement that other people compare their servers with. Deleting it would rewrite the leaderboard for people who asked for nothing. The right to erasure covers your personal data, and that is what goes: the report keeps the measurement, not you.

Two cases cannot be handled from this page: an administrator account, and an account referenced by a hosting provider's certification request. Write to [email protected].