# Authentication and task security

Use the official browser flow, verify account identity, review authorized devices, revoke unknown sessions, and reset credentials after suspicious activity.

![Authentication and task security in Foxora v5.0.3](/docs/images/v5.0.3/settings/permissions.webp)

## Where this lives

Open the relevant section under **Settings → Permissions** or **Settings → Data**.

Foxora security is layered across account authentication, local project access, session autonomy, agent tools, browser and computer control, connected services, and local data storage.

> **Safety:** No autonomy mode can make an external action reversible. Use separate test environments, least privilege, independent verification, and prompt incident response for suspected credential exposure.

## Steps

1. Open the relevant section under **Settings → Permissions** or **Settings → Data**.
2. Use the official browser flow.
3. Verify account identity.
4. Review authorized devices.
5. Revoke unknown sessions, and reset credentials after suspicious activity.
6. **Confirm the result.** Review the transcript and external audit records, inspect authorized devices and connections, and test that revoked access no longer works.

## Choose the right path

- Use local sessions and Memory Den for device-resident work.
- Use Composio authorization for supported plugin accounts.
- Use an agent’s dedicated BYOK field for model-provider keys.


## Confirm it worked

- Review the transcript and external audit records, inspect authorized devices and connections, and test that revoked access no longer works.
- The screen, command, file, run, or destination named in this guide reflects the expected state.
