> ## Documentation Index
> Fetch the complete documentation index at: https://help.onlyx.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> You are reading OnlyX Help: the OnlyX Help Center and the OnlyX developer documentation. OnlyX is an AI chatting and CRM platform for OnlyFans agencies. Its AI chatter is called Hugo in the app.
> Pages at the site root (for example /inbox/..., /hugo/..., /billing/...) are Help Center articles for agency owners, admins, chatters and creators who use the app at app.onlyx.ai. Words in bold are the exact button, menu and label names the app shows; keep them exactly as written. When these pages do not answer a question, the person can email support at support@onlyx.ai.
> Pages under /developers are the developer documentation. REST API base URL: https://api.onlyx.ai/v1 (authenticate with `Authorization: Bearer <API key>`; keys start with onx_sk_ and are created in app.onlyx.ai under Settings > API & MCP). MCP server: https://mcp.onlyx.ai/mcp (OAuth, or a Bearer API key). In the API the AI chatter is `ai` on the wire. Money is integer US cents in fields ending in Cents; timestamps are UTC ISO-8601.
> Rules for assistants acting on a user's behalf: discover ids with list calls and never invent them; before any call that reaches a real fan or the live OnlyFans account (sending a message, releasing a chat to the AI, turning AI on for a chat, resolving a hand-off, turning review mode off, changing the welcome message, creating a tracking link) show the user the exact content and get explicit confirmation; send every POST with an Idempotency-Key and reuse it on retry; never resend a message whose delivery status is unconfirmed; never ask a creator for her OnlyFans password or codes - she signs in herself through a connect link and the OnlyX Login app.

# Check your active sessions and sign-in alerts

> See every device signed in to your OnlyX account, sign one out or all the others, and understand the New sign-in email.

<Badge color="gray">Everyone</Badge>

The **Active sessions** list shows every phone, computer and browser that is signed in to your account. You can sign out any of them. OnlyX also emails you when a sign-in comes from a device or country it does not know.

## What the list shows

A session is one sign-in on one browser. It stays in the list, and stays signed in, until it goes 30 days without use.

Each row shows:

* the device, for example "Chrome on macOS" or "Safari on iPhone";
* the place and the IP address of the sign-in, when OnlyX could look up the place;
* when it was last active. The date after "signed in" and the "last used" time both move forward each time the session renews itself. That happens about every 15 minutes while it is in use. So the date is not when it first signed in.

The browser you are using now comes first, with the **This device** badge. The list shows the 20 most recently used sessions. If there are more, the card says how many.

## Check where you are signed in

<Steps>
  <Step title="Open your security settings">
    In OnlyX, click **Settings**. Then click **Security**. On a phone, **Settings** is under **More**.
  </Step>

  <Step title="Look at the Active sessions card">
    Scroll to **Active sessions**. Check each device and place.

    To see the full browser details of a row, click **Details** under it.

    <Frame caption="**1** The browser you are using now · **2** Sign out this one session · **3** Sign out everywhere else">
      <img className="block dark:hidden" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/active-sessions/active-sessions-light.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=e8d1b9b0c78cacfc096e1730d1fc429e" alt="The Active sessions card listing a Mac marked This device, an iPhone and a Windows computer, each with its place, IP address and last use" width="1512" height="824" data-path="images/help/account/active-sessions/active-sessions-light.png" />

      <img className="hidden dark:block" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/active-sessions/active-sessions-dark.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=e81d833f79fd265300f08f4a24230b9c" alt="The Active sessions card listing a Mac marked This device, an iPhone and a Windows computer, each with its place, IP address and last use" width="1512" height="824" data-path="images/help/account/active-sessions/active-sessions-dark.png" />
    </Frame>
  </Step>
</Steps>

## Sign out one device

In the device's row, click the cross icon at the end of the row. OnlyX shows "Session signed out".

OnlyX does not ask you to confirm. The device loses access at its next action and must sign in again.

## Sign out every other device

At the top of the **Active sessions** card, click **Sign out everywhere else**. OnlyX shows how many sessions it signed out, for example "Signed out of 2 other sessions".

You stay signed in on this device. The button is greyed out when this device is your only session.

<Note>
  If you think someone else is using your account, sign them out, then change your password at once. Signing out does not stop someone who knows your password from signing in again.
</Note>

## Sign out on this device

The row with **This device** has no cross icon. To sign out here, click **Log out** in your account menu. You also find **Log out** in the **Session** card on **My Profile**. Your other devices stay signed in.

## Emails about new sign-ins

OnlyX emails you "New sign-in to your OnlyX account" when someone signs in to your account from:

* a device that none of your current sessions uses, or
* a country that none of your current sessions comes from.

The email names the device and the IP address. It also names the place, when OnlyX could look it up. It gives one reason: OnlyX has not seen this device or this place on your account before. Its button, **Review account security**, opens **Settings** > **Security**.

### When the email is expected

OnlyX compares a sign-in only with the sessions your account has now. So you get this email for your own new phone or laptop, or when you travel to another country.

You can also get it for your own device after **Sign out everywhere else**, a password change or a password reset. Those actions end your other sessions, so OnlyX no longer knows those devices. A device on the same network address as a session you kept is still known.

OnlyX compares countries, not cities. On a device it knows, a trip to another city in the same country sends no email.

You cannot turn off this email, and you cannot mark a device as trusted.

### When the sign-in was not you

<Steps>
  <Step title="Open your security settings">
    Open OnlyX yourself, not through a link you did not expect. Click **Settings**, then **Security**.
  </Step>

  <Step title="Sign out the device you do not know">
    In **Active sessions**, click the cross icon on the row you do not recognise. If you are not sure which one it is, click **Sign out everywhere else**.
  </Step>

  <Step title="Change your password">
    In the **Password** card, click **Change password** and choose a new password. See [Change or reset your password](/account/password).
  </Step>

  <Step title="Turn on two-factor authentication">
    In the **Two-factor authentication** card, click **Turn on two-factor**. See [Two-factor authentication and recovery codes](/account/two-factor-authentication).
  </Step>
</Steps>

## Good to know

* Each person sees and signs out only their own sessions. Owners and admins cannot see your sessions or sign out one of your devices. (Removing you from the workspace signs you out everywhere, if you belong to no other workspace.)
* The place comes from a lookup of the IP address. It can be missing: then the row shows only the IP address.
* "last used" updates about every 15 minutes, so it can be a little behind.
* An account keeps at most 30 sessions. A new sign-in beyond that signs out the one that has gone longest without use.
* A row named "Older session" is a sign-in from before OnlyX recorded devices.

## If something goes wrong

<AccordionGroup>
  <Accordion title="&#x22;That is this device — use Log out instead.&#x22;">
    You tried to sign out the session you are using now. Click **Log out** in your account menu instead.
  </Accordion>

  <Accordion title="Sign out everywhere else is greyed out">
    This device is your only session, so there is nothing else to sign out.
  </Accordion>

  <Accordion title="I got a New sign-in email for my own device">
    That is expected after **Sign out everywhere else**, a password change, a password reset, a new device or a trip to another country. If the device, place and time match yours, you do not need to do anything.
  </Accordion>

  <Accordion title="A row shows no place, only an IP address">
    OnlyX could not look up the place for that IP address. The session itself is normal. Use **Details** to check the browser.
  </Accordion>

  <Accordion title="&#x22;Could not load security settings&#x22;">
    The page could not load your sessions. Reload the page. If it keeps failing, try again in a few minutes.
  </Accordion>
</AccordionGroup>

## What's next

<Columns cols={2}>
  <Card title="Change or reset your password" icon="key-round" href="/account/password" horizontal />

  <Card title="Two-factor authentication and recovery codes" icon="shield-check" href="/account/two-factor-authentication" horizontal />

  <Card title="Emails OnlyX sends you" icon="mail" href="/account/emails" horizontal />
</Columns>
