Account Security Settings

Protect your account with strong passwords and two-factor authentication

Account Security Settings

Protecting your account is essential. We provide several security features to keep your services and data safe.

Accessing Security Settings

  • Navigate to Dashboard → Profile
  • Click the Security tab
  • View and configure your security options
  • [Screenshot: Security settings page]

    Password Management

    Changing Your Password

    To update your password:

  • Go to the Security tab in your profile
  • Click Change Password
  • Enter your current password
  • Enter and confirm your new password
  • Click Update Password
  • Password Requirements

    Your password must:

    • Be at least 8 characters long
    • Include a mix of letters, numbers, and special characters (recommended)
    • Be unique and not used on other websites

    Password Reset

    If you've forgotten your password:

  • Click Forgot Password on the login page
  • Enter your email address
  • Check your email for reset instructions
  • Follow the link to create a new password
  • Two-Factor Authentication (2FA)

    Two-factor authentication adds an extra layer of security by requiring a second verification code when you log in.

    Setting Up 2FA

  • Navigate to Security settings
  • Click Enable Two-Factor Authentication
  • Scan the QR code with your authenticator app (Google Authenticator, Authy, etc.)
  • Enter the verification code from your app to confirm
  • Save your backup codes in a safe place
  • [Screenshot: 2FA setup with QR code]

    Using 2FA

    When 2FA is enabled:

    • Log in with your email and password as usual
    • Enter the 6-digit code from your authenticator app
    • Optionally check "Trust this device" to skip 2FA for 30 days on this device

    Backup Codes

    Backup codes let you access your account if you lose access to your authenticator app:

    • You'll receive backup codes when enabling 2FA
    • Store them securely (not on the same device as your authenticator)
    • Each code can only be used once
    • Generate new codes if you run out

    Disabling 2FA

    If you need to disable 2FA:

  • Go to Security settings
  • Click Disable Two-Factor Authentication
  • Enter a verification code or backup code
  • Confirm the change
  • Session Management

    View and manage your active login sessions:

    • See all devices currently logged into your account
    • View login times and locations
    • Sign out from specific devices or all devices at once
    [Screenshot: Active sessions list]

    Login History

    Review your account's login activity:

    • See recent login attempts and times
    • Check IP addresses and locations
    • Identify any suspicious activity

    Best Practices

    • Never share your password with anyone
    • Use a unique password not used on other sites
    • Enable two-factor authentication for maximum security
    • Review login history regularly for suspicious activity
    • Keep your email secure as it's used for account recovery
    • Update your password periodically (every 3-6 months recommended)
    • Sign out when using shared or public computers

    If Your Account Is Compromised

    If you suspect unauthorized access:

  • Change your password immediately
  • Enable two-factor authentication if not already active
  • Sign out all other sessions in Session Management
  • Review recent account activity for any unauthorized changes
  • Contact support if you notice suspicious orders or changes