Sign-in & your Blessed Bits account
One account for every Blessed Bits product. Use Google, Apple, or email — with extra security you set once.
Last updated: August 25, 2026
On this page
- Why does Blessed Bits handle sign-in?
- What are the advantages?
- Can I use Google or Apple?
- What is “email me a code”?
- Why did I get two codes?
- Why doesn’t Google or Apple also send an email code?
- Email sign-in vs email 2FA
- How do I manage this across products?
- Which extra security method should I use?
- Still need help?
Why does Blessed Bits handle sign-in?
Products focus on delivering the value of each product, instead of making you repeat a separate sign-in for every app. Blessed Bits provides single sign-on (SSO): you choose email or a social platform you already use (Google or Apple), and that same sign-in works across Blessed Bits products.
Blessed Bits then lets you turn on an extra layer if you want it: two-factor authentication (2FA). 2FA can use:
- TOTP (time-based one-time password) — a 6-digit code from an authenticator app such as Google Authenticator, Microsoft Authenticator, or Authy. The code changes about every 30 seconds and is the strongest everyday option.
- SMS — a code texted to your phone.
- Email — a code sent to your inbox.
Blessed Bits does identity: same account, same security, same recovery. Apps never keep your password or 2FA secrets.
What are the advantages?
- Use an account you already have. Continue with Google or Apple, or have us email a one-time code. You do not have to invent a new password for every product.
- Industry best practice, applied consistently. Sign-in proves you own Google, Apple, or your inbox. Extra security (2FA) is a different check — not the same inbox twice.
- Set security once. Turn on a text message or authenticator app in one place. Every Blessed Bits product that uses this account will ask for it.
- Centralized account management. Update email, phone, or 2FA once. If you use more than one Blessed Bits product, you are the same person in all of them.
- Less to steal from any one app. Individual products never store your password or 2FA secrets. That reduces the blast radius if a single app has a problem.
Can I use Google, Apple, or X?
Yes. Continue with Google, Apple, or X uses an account you already have. After that provider confirms it is you, Blessed Bits still asks for your extra security if you have turned 2FA on. Native apps use Apple, Google, or email.
We ask those services for an email so we can match you to an existing Blessed Bits account. The first time a new sign-in method matches an account you already have, Blessed Bits asks you to confirm the link before that method can open the account. After you confirm, later visits with the same method skip that step.
We only use that provider to prove it is you and to match email. For X, that is your X user id and email. We do not read your posts, messages, or other X data. X’s own permission screen may list extra items we cannot turn off — their login API requires them even for sign-in only.
If the email does not match (or they hide it / do not send one), this sign-in will not connect to a profile you made with a different email or another provider. You will see a warning and can continue with a separate profile, or go back and use the method you used before.
Apple may offer Hide My Email. X may list “email address” in its permission screen, but it does not ask Share vs Hide the way Apple does — and it may skip that screen if you already authorized the app. Same outcome either way: no silent merge.
What is “email me a code”?
It is passwordless sign-in. We email a 6-digit code to prove you can open that inbox. That is your first check — the equivalent of a password — not the extra security step.
The code is short-lived and one-use. If you did not request it, you can ignore the message.
Why did I get two codes?
If you signed in with email and your account has SMS or authenticator 2FA turned on, you will see two steps on purpose:
- Email code — proves you own the inbox (sign-in).
- Text or authenticator code — extra protection you turned on in account settings.
This is not a duplicate login. It is two different checks, on two different channels (inbox, then phone or authenticator).
We do not skip the second step after an email code. Skipping it would leave the account protected only by the inbox — which is not industry best practice for accounts that enrolled 2FA.
If your extra security method is also email, we do not send a second email code. The same inbox would not add protection.
Why doesn’t Google or Apple also send an email code?
Google and Apple already completed the first check. If extra security is on, you only complete that Blessed Bits step (email, SMS, or authenticator — whichever you chose).
| How you sign in | If extra security is off | If extra security is on |
|---|---|---|
| Google or Apple | You’re in | One extra code (email, SMS, or authenticator) |
| Email me a code | You’re in after the email code | SMS or authenticator still required. Email 2FA is not asked twice. |
| Email and password (web) | You’re in | One extra code (email, SMS, or authenticator) |
What’s the difference between email sign-in and email 2FA?
- Email sign-in is the first factor: a 6-digit code (or a password) that proves you can open the inbox.
- Email 2FA is extra security that also uses email. It is the lightest option. We will not stack it on top of email sign-in.
- SMS or authenticator 2FA is extra security on a different channel. That is the recommended pairing with email sign-in, Google, or Apple.
How do I manage this across Blessed Bits products?
Security settings live with your Blessed Bits account, not inside each product. Change your method once — the next sign-in in any Blessed Bits product uses it.
From a product, open account or security settings (or the 2FA screen). From the web, use your Blessed Bits account.
If you use several Blessed Bits solutions, you should see the same email, the same linked Google or Apple account, and the same extra-security method everywhere. That is the point of centralized account management.
Which extra security method should I use?
- Authenticator app (TOTP) — time-based one-time password. A 6-digit code from Google Authenticator, Microsoft Authenticator, or Authy that changes about every 30 seconds. Strongest everyday option. Look for Blessed-Bits.com in the app.
- SMS — a real second factor (phone vs inbox). Useful if you do not want an authenticator. Message rates may apply; consent is required.
- Email 2FA — convenient, weaker, because it uses the same inbox as email sign-in.
You can change methods later. Keep backup codes if the product offers them, in case you lose the phone.
Still need help?
If a code never arrives, wait for the resend timer, check spam, and confirm the email or phone on the account is current. For account recovery or a locked sign-in, contact support@blessed-bits.com or use the contact form.
Questions about your account?
Email support@blessed-bits.com · Contact form · Privacy · Terms