> ## Documentation Index
> Fetch the complete documentation index at: https://help.the-meridian.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Login history

Login history records every sign-in attempt on your account, both the ones that worked and the ones that did not. It sits in your account's **Security** section, under **Login history**.

## What each attempt records

| Column | Notes |
| - | - |
| Time | When the attempt was made |
| IP | Where it came from |
| Device | The browser and platform that made it |
| Result | What happened. See below |

The list is paginated, newest first, and shows the range you are viewing against the total.

## Results

| Result | Meaning |
| - | - |
| **Successful** | Credentials were accepted and the session was created. With [2FA](/2-fa) on, only once the code was accepted too |
| **Password accepted, 2FA not completed** | The password (or passkey, or social sign-in) was accepted, but no correct authenticator code followed: the sign-in was abandoned, timed out or refused |
| **Failed** | The credentials were wrong |
| **Failed: wrong 2FA code** | The password was right, but the code from the authenticator app was not. See [2FA](/2-fa) |
| **Blocked: suspicious** | Credentials were correct, but the attempt looked risky enough to lock the account pending your approval |
| **Blocked: locked** | The account was already locked when the attempt arrived |
| **Blocked: closed account** | The account no longer exists |

The three blocked results are the useful ones. **Blocked: suspicious** in particular means someone had your password: it was accepted, and only the risk check stopped the sign-in.

## When something looks wrong

A **Failed** row you do not recognize is someone guessing. A **Failed: wrong 2FA code** or **Password accepted, 2FA not completed** row you do not recognize means someone has your password: change it. A **Successful** row you do not recognize is someone who got in.

For the second, change your [password](/password), which ends every other session, browser and CLI alike, then check [Active sessions](/sessions) and revoke anything left. Turning on [2FA](/2-fa) stops a stolen password being enough on its own.

<Note>
  Meridian evaluates risk **after** your credentials are accepted, so a correct password on a new device, from a new country, or at an unusual hour can still be stopped. See [Suspicious sign-ins](/suspicious-login) for the signals and how to approve one.
</Note>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.