
Turn On Two-Factor Authentication
Your account holds real credits and live tokens. If your password is reused anywhere else, a breach somewhere unrelated can reach your API keys. Two-factor authentication closes that gap.

Enable it in two minutes ⏱️
- Open Settings -> Security -> Two-factor authentication
- Scan the QR code with Google Authenticator, 1Password or Authy
- Enter the six-digit code to confirm
- Save the recovery codes somewhere safe
| Step | Where | Time |
|---|---|---|
| Install an authenticator app | App store | ~1 min |
| Scan the QR code | Settings -> Security | ~30s |
| Confirm with a code | Authenticator app | ~20s |
| Store recovery codes | Password manager | ~1 min |
What changes afterwards ✨
Every new login asks for your password plus a code from the authenticator app. API calls are unaffected — two-factor only guards the panel, not your tokens.
Keep recovery codes handy 🧾
If you lose your phone, recovery codes are the only way back in. Store them in a password manager rather than a note on the device you authenticate with.
Frequently asked questions ❓
Does 2FA slow down API requests?
No. It only applies to logging in to the web panel; server-to-server API calls keep using tokens as before.
Which apps work?
Any TOTP app — Google Authenticator, Authy, 1Password, Bitwarden and most others.
What if I lose my phone?
Use one of your recovery codes to log in, then set up 2FA on a new device.
Comments (0)