Settings

The Settings page lets you manage your account, security, and member configuration on ThreatExchange. To access it, click Settings in the sidebar navigation.

Settings page overview showing the sidebar navigation and tab layout

Settings are organized into tabs. The Profile and Password & Security tabs are available to all users. The Member and People tabs appear when you are acting as a member and provide additional configuration for that member.

Profile

The Profile tab manages your personal account information. You can update your display name and view the email address associated with your account.

Pending invitations

If you have been invited to join a member, a table of pending invitations appears below your profile information. Each invitation shows the member name and expiration date.

  • Click Accept to join the member. You will be prompted to confirm before the invitation is accepted.
  • Click Decline to reject the invitation. You will be prompted to confirm before the invitation is removed.
Profile tab showing name, email, and pending invitations table

Password & Security

The Password & Security tab lets you manage your login credentials and two-factor authentication.

Password and Security tab with change password form and two-factor authentication status

Change password

To update your password:

  1. Enter your current password.
  2. Enter a new password that meets the strength requirements shown at the top of the form.
  3. Re-enter the new password to confirm.
  4. Click Update Password.

If the update fails, verify that your current password is correct and that your new password meets all requirements.

Two-factor authentication

This section shows whether two-factor authentication (2FA) is enabled on your account.

  • If 2FA is not enabled, a notice prompts you to set it up. Click Set up two-factor authentication to begin the setup process.
  • If 2FA is enabled, a table lists your registered authentication methods, including the method type, date added, and date last used.
Two-factor authentication methods table showing registered authentication methods

Member

The Member tab displays information about the member you are currently acting as. This tab is only visible when you have selected a member. You can view your member name, check whether your member has API access, and manage invite settings.

Member tab showing member name, API access status, and invite settings

Allow invites from Developer Dashboard

This toggle controls whether admins of your member can invite new users from the Facebook Developer Dashboard. When disabled, invitations can only be sent from threatexchange.meta.com. We recommend disabling this feature once an account is onboarded and manage directly on ThreatExchange.

Editing this setting is only available to administrators.

People

The People tab shows everyone associated with your member, including active users and pending invitations, in a single table.

People tab showing active users and pending invitations in a unified table

The table includes the following columns:

  • Name — The user's display name. Pending invitations show a dash.
  • Email — The user's email address, or the email the invitation was sent to.
  • Role — Administrator or User. Pending invitations show a dash.
  • StatusActive for current users. Invited for pending invitations, with the expiration date.

Inviting a user

Administrators can invite new users by clicking the Invite button at the top of the page. Enter the person's email address in the modal and click Invite. The invitation appears in the table with a status of Invited until the recipient accepts or the invitation expires.

Canceling an invitation

Administrators can cancel a pending invitation by clicking Cancel in the Actions column. You will be prompted to confirm before the invitation is revoked.

Changing a user's role

Administrators can change another user's role between Administrator and User. Click Edit in the Actions column, select the new role from the dropdown, and save.

At least one administrator is required on every member. You cannot change the role of the last remaining administrator.

Removing a user

Administrators can remove a user from the member by clicking Remove in the Actions column. You will be prompted to confirm before the user is removed. Removed users immediately lose access to the member.

At least one administrator is required on every member. You cannot remove the last remaining administrator.

Next steps

  • UI Overview — Learn about the ThreatExchange UI and its use cases.
  • Members Tab — View participating members on ThreatExchange.
  • Getting Access — Set up API access for your member.
  • FAQ — Common questions about ThreatExchange.