Account security: login, devices and tokens

Your Primfeed account is tied to your Second Life avatar, and the Security tab in your settings is where you control how you sign in and who has access: your login method, your password, the devices that are signed in, and the viewer (TPV) tokens that can post for you. Everything here is part of your account at no extra cost; none of these security tools require Primfeed Pro.

Written By Luke Rowley

Last updated About 11 hours ago

Open your Security settings

  1. Click your profile picture in the sidebar to open your account menu.

  2. Click Settings.

  3. In the settings dialog, choose Security from the Account list on the left.

You'll see these sections, in order: New device notifications, OTP Login, Change your password, Connected devices, TPV Tokens, and Danger zone.

Tip: Most settings in this dialog save the moment you change them; there's no separate Save button on the dropdowns. The one exception is the password form, which has its own Change the password button.

Sign in with an in-world code (OTP)

You don't need a password to get into Primfeed. On the login page you can choose Login with in-world code, and Primfeed sends a one-time code straight to your avatar's local chat in Second Life.

  1. On the login page, choose Login with in-world code.

  2. Type your legacy avatar name (the same name shown as the placeholder, e.g. "Luke Rowley") and click Send the in-world code.

  3. Switch to Second Life. A sender named "Primfeed - Security System" sends an 8-digit code to your local chat.

  4. Back on Primfeed, type the 8-digit code to sign in.

A few things worth knowing:

  • The code expires after 10 minutes.

  • You can request a limited number of codes in a short window. If you ask for too many, you'll be asked to wait a little while before trying again.

Tip: The in-world code arrives in local chat, not as an instant message, so make sure you're standing somewhere you can see your chat, and that local chat isn't muted.

Turn the in-world code login on or off

In Security → OTP Login, the dropdown lets you set OTP login to Enabled or Disabled. It's Enabled by default. When it's disabled, no one can sign in to your account using an in-world code, and they'll need your password instead.

Warning: If you've never set a password and you disable OTP Login, you'll lock yourself out of your account. Set a password first (see below) before switching this off.

If you need to enable your in-world code login, you can do so at the Primfeed’s mainstore.

Set or change your password

If you'd rather sign in with a username and password, you can set one in Security → Change your password. This is also where you change an existing password.

  1. In Change your password, type a new password in the New password field.

  2. A Confirm new password field appears, so type the same password again.

  3. Click Change the password.

Once it's saved, you can sign in from the login page using Sign in with password.

Tip: Forgot your current password? You don't need it to get back in. Use Login with in-world code on the login page, then come here to set a new password.

Get alerted when a new device signs in

In Notifications → Security, the New device connections is set to Enabled by default. While it's on, Primfeed sends you a notification whenever your account is signed in from a device it doesn't recognize, so you can spot any access you didn't expect. You can switch it to Disabled if you'd rather not receive these alerts.

Review and remove connected devices

Security → Connected devices lists every active sign-in session on your account. Each one shows:

  • The browser (Chrome, Firefox, Safari, Edge, or "Unknown browser")

  • The device type and operating system

  • A First seen date (hover the info icon) and a Last used time

  • A green Current badge on the session you're using right now

To end a session (for example, a device you no longer use or don't recognise), click the Delete button on that row. That device is signed out immediately and will need to log in again.

Tip: See a device you don't recognise? Delete it, then change your password right away so the old sign-in can't be used again.

Manage viewer (TPV) tokens

When you link a Third-Party Viewer like Firestorm so it can post pictures on your behalf, Primfeed stores a TPV token for that viewer. You'll find them in Security → TPV Tokens.

Each token shows an In use badge, the viewer's name and icon, and when it was Last used. To remove a viewer's access, click Delete on its row, and the integration is removed so that viewer can no longer post for you until you link it again.

If you haven't linked a viewer yet, this section instead points you to download the latest Firestorm version to get started. For the full linking walkthrough, see Connect your Second Life viewer so you can post in-world.

Tip: A linked viewer can only verify your identity and create posts for you. It cannot see or change your password, change your settings, or like and comment on posts. Removing its token here is always safe and won't affect your account's other access.