Account Security Settings
Protect your account with strong passwords and two-factor authentication
Account Security Settings
Protecting your account is essential. We provide several security features to keep your services and data safe.
Accessing Security Settings
- Navigate to Dashboard → Profile
- Click the Security tab
- View and configure your security options
[Screenshot: Security settings page]
Password Management
Changing Your Password
To update your password:
- Go to the Security tab in your profile
- Click Change Password
- Enter your current password
- Enter and confirm your new password
- Click Update Password
Password Requirements
Your password must:
- Be at least 8 characters long
- Include a mix of letters, numbers, and special characters (recommended)
- Be unique and not used on other websites
Password Reset
If you've forgotten your password:
- Click Forgot Password on the login page
- Enter your email address
- Check your email for reset instructions
- Follow the link to create a new password
Two-Factor Authentication (2FA)
Two-factor authentication adds an extra layer of security by requiring a second verification code when you log in.
Setting Up 2FA
- Navigate to Security settings
- Click Enable Two-Factor Authentication
- Scan the QR code with your authenticator app (Google Authenticator, Authy, etc.)
- Enter the verification code from your app to confirm
- Save your backup codes in a safe place
[Screenshot: 2FA setup with QR code]
Using 2FA
When 2FA is enabled:
- Log in with your email and password as usual
- Enter the 6-digit code from your authenticator app
- Optionally check "Trust this device" to skip 2FA for 30 days on this device
Backup Codes
Backup codes let you access your account if you lose access to your authenticator app:
- You'll receive backup codes when enabling 2FA
- Store them securely (not on the same device as your authenticator)
- Each code can only be used once
- Generate new codes if you run out
Disabling 2FA
If you need to disable 2FA:
- Go to Security settings
- Click Disable Two-Factor Authentication
- Enter a verification code or backup code
- Confirm the change
Session Management
View and manage your active login sessions:
- See all devices currently logged into your account
- View login times and locations
- Sign out from specific devices or all devices at once
[Screenshot: Active sessions list]
Login History
Review your account's login activity:
- See recent login attempts and times
- Check IP addresses and locations
- Identify any suspicious activity
Best Practices
- Never share your password with anyone
- Use a unique password not used on other sites
- Enable two-factor authentication for maximum security
- Review login history regularly for suspicious activity
- Keep your email secure as it's used for account recovery
- Update your password periodically (every 3-6 months recommended)
- Sign out when using shared or public computers
If Your Account Is Compromised
If you suspect unauthorized access:
- Change your password immediately
- Enable two-factor authentication if not already active
- Sign out all other sessions in Session Management
- Review recent account activity for any unauthorized changes
- Contact support if you notice suspicious orders or changes