Security changes
The Security Changes group (lock icon) in the middle column holds operations that make real changes to the account's security — not information checks. Some of these are irreversible. For actions that produce new secrets (password, 2FA key, app password), the tool writes the new value back to the account's row in the database — make sure those values are preserved, or you may lock yourself out of the account.
This entire group makes real security changes. After each sensitive action, Google may raise a re-authentication challenge (password / TOTP / WebAuthn) — the tool handles it automatically, but understand these are consequential and some are permanent.

Remove Recovery Phone
Remove Recovery Phone (also detects Phone Hidden) — when ON, the tool removes the recovery phone number from the account (and also detects a "Phone Hidden" state).
Irreversible: the phone number is actually removed from the account. Google requires re-authentication (including a WebAuthn challenge) after pressing Remove. The number can live in 3 places and the confirm dialog comes in 2 forms — all handled automatically.
Change Recovery Email — pick the new recovery-email source
When you turn Change Recovery Email ON (label: idle 4 days recommended), a panel appears with a “Take the new recovery email from” dropdown. You pick exactly one source — the tool uses that source, it does not auto-guess.
| Source | Meaning |
|---|---|
| The “New Recovery Email” column of each account Default | Each account uses the value you entered in its New Recovery Email cell (Accounts tab, or via Excel import / paste). Accounts with an empty cell are skipped. |
| Each account's column, falling back to a shared recovery email | Hybrid: accounts that filled their own cell use it; accounts with an empty cell fall back to the shared email you enter below (instead of being skipped). Reveals a shared-email box. |
| One recovery email shared by all | Shows an input; every account is changed to this same recovery email, regardless of its own cell. |
- Turn on
Change Recovery Email— the panel expands. - Pick a source in Take the new recovery email from.
- If “shared by all” — type the address in the
New recovery email (all accounts)box that appears. - Press
Save Features.
Real security change: the recovery email is changed on the account.
Change Password — pick the new-password source
When you turn Change Password ON (label: idle 4 days recommended), a panel appears with a “Take the new password from” dropdown — three sources. Pick one and the tool uses exactly that.
| Source | Meaning |
|---|---|
| The “New Password” column of each account Default | Each account uses the value in its New Password cell (Accounts tab, or via import / paste). Accounts with an empty cell are skipped. |
| Each account's column, falling back to a shared password | Hybrid: accounts with their own cell use it; accounts with an empty cell fall back to the shared password you enter below. Reveals a shared-password box. |
| One password shared by all | Shows an input; every account is changed to this same password (placeholder e.g. MyNewP@ss2026). |
| Auto-generate a unique strong one per account | Shows a Password length box (12–64, default 16); each account gets its own unique strong password. |
- Turn on
Change Password— the panel expands. - Pick a source in Take the new password from.
- If “shared by all” — type the password. If “auto-generate” — set the length.
- Press
Save Features.
Irreversible: the account password is actually changed. If the new password isn't recorded you can lock yourself out. In auto-generate mode each account gets a unique strong password — the tool writes the new value back to the account row, but make sure results are captured (use Export to retrieve them). The length input silently clamps to 12–64 (defaults to 16 on invalid input).
Why “per-account” is gone: the old version auto-prioritised the per-account column then fell back to a shared value, leaving many unsure which was active. Now you pick the source directly. Old settings are auto-migrated to the matching source (shared mode → “one shared value”, generator → “auto-generate”, otherwise → “each account's column”), nothing is lost.
Two-step verification & app passwords
These three toggles are tightly linked: App Password requires 2FA to be enabled.
| Toggle | What ON does | Requirement / notes |
|---|---|---|
| Enable 2-Step Verification (2FA) (idle 4 days) | Turns on 2-Step Verification (authenticator-based 2FA) and stores the generated secret. | A prerequisite for Create App Password. Label recommends idling the account ~4 days first. |
| Change Authenticator Key (2FA) (idle 4 days) | Rotates the existing authenticator (2FA) key to a new secret. | Requires 2FA to already exist. The old authenticator entry stops working; the new secret (two_fa_secret) must be stored. |
| Create App Password (requires 2FA) | Generates an app-specific password. | Requires 2FA already enabled — without it Google does not offer app passwords. The app-password name field validates real keystrokes, so the tool fills it with a trusted-input method. |
Enable 2FA and Change Authenticator Key are major, effectively irreversible changes: the account gains a 2FA secret that must be preserved (it's needed for future logins). The tool writes the new secret back to the database (two_fa_secret). Losing this secret = losing the ability to log in.
Sign out all devices
Sign out all devices — when ON, the tool signs the account out of all other devices/sessions.
Loops through the device-activity list and signs out every session except the current device. May trigger a re-authentication (password / WebAuthn) partway through — handled automatically. Every other logged-in session on those devices is terminated.
Confirm Security Activity — runs last
Confirm Security Activity (Yes, it was me — runs last) — when ON, after the security changes the tool opens the security notifications and clicks Yes, it was me on the alerts, so the account doesn't stay flagged with a "New" security alert.
- Turn on
Confirm Security Activity. - Press
Save Features. - Run accounts — this step always runs last (after all other security changes) so it can dismiss the alerts they generate.
Best paired with the other Security Changes toggles. On its own it just confirms whatever alerts already exist.