Profile and security
Your identity on Kops, what the community can see of it, and the two screens that decide who can get into your account — plus the thing a passkey changes about signing in, which is more than it looks.
Settings → Account, in the user menu. Three sections: Profile, Sessions, Passkeys.
Profile

The tab opens on your generated identity, then the public profile, and ends with the two things you cannot change: your email and your member since date.
New name re-rolls the generated identity, and it is limited to once every 30 days. The button is disabled in between, and both the tooltip and the line under it name the date it unlocks.
The limit exists so a name means something. A name that can be changed hourly is not an identity anybody can recognise.
The public profile
Off by default, and it is the switch that reveals everything else in the section — with it off, there is no username, no bio and no photo to fill in.
Turn it on and you get:
| Photo | JPG or PNG, up to 2 MB. Change photo to replace it |
| Username | Letters, numbers and _, 3–30 characters. Checked for availability as you type — Available, Already taken, or the rule itself if the shape is wrong |
| Bio | Up to 280 characters, with a live counter |
Then four switches under Show on profile, each independent:
- Subscription tier
- Cop count
- Success rate
- Buy-attempt heatmap — the only one that starts on. It says how often you hunt, never what you bought or what you paid.
You can show a cop count without a success rate, or a tier without either.
None of this exposes your Vinted accounts, your filters, or what you buy. It is a scoreboard, not a shop window.
Your username is separate from the generated name: the generated one is what the community sees by default, the username is what you choose to be called on top of it.
Sessions
Devices where you're currently logged in.

Your current session sits in its own block at the top, marked Current, and it reads Active now — that badge is what "this is you, here" means, not "this device is live". Every other session shows when it was last active, and its IP address beside it.
Each is named by its browser and operating system, which is usually enough to recognise a machine.
End this session — the bin on a row — signs that device out. End all clears every other session in one go, confirms how many it ended, and leaves you signed in here.
If you see a device you do not recognise, end that session, then change your password. In that order: ending the session first stops whatever is happening while you deal with the password.
Signing out one device does not affect the others, and it does not affect your connected Vinted accounts — those are a separate thing entirely. See Adding a Vinted account.
Passkeys
A passkey signs you in with your device's biometrics — Face ID, a fingerprint, a Windows Hello PIN — or a hardware security key. No password to type, and nothing to phish.

Add passkey, then give it a name you will recognise later (MacBook Pro, iPhone). Your browser handles the rest.
The list shows each passkey with when it was added and when it was last used — or Never used. The pencil renames one; the bin removes it, with a confirmation.
| Browser does not support it | You are told, with a suggestion to use a current Chrome, Safari, Firefox or Edge |
| You have several devices | Add one passkey per device; they are independent |
| You remove your last passkey | Your password alone signs you in again |
The moment you have one passkey, a password on its own stops being enough. Signing in with your password lands you on Verify your identity instead of in the dashboard — every time, on every device, including devices that have no passkey of their own.
That is the point of it, and it is worth knowing before you add one on a machine you are about to travel without.
If you cannot present a passkey, Sign in with email link on that same screen sends you one. It lasts 10 minutes, works once, and gets you in — from where you can remove the passkey you no longer have.
Removing your last passkey puts password sign-in back to normal.
A passkey is cryptographically tied to the domain it was created on, and Kops moved. One created before the move cannot open kops.gg — nothing can convert it.
The Passkeys tab shows a banner saying so, dismissible once you have dealt with it, and the sign-in screen offers the email link for exactly this case. Sign in with the link, delete the old passkey, register a new one.
Adding, renaming and removing a passkey are all recorded in your workspace's audit log.