Skip to main content
HelpKnowledge baseCompliance & Security
Compliance & Security

Setting up two-factor authentication

Turn it on before you connect a live account. Store the recovery codes somewhere else.

An account that can place trades deserves a second factor.

Setting it up

  1. Settings → Security → enable 2FA.
  2. Scan the QR code with any TOTP app — Authy, 1Password, Google Authenticator.
  3. Confirm with a code. This proves the app works before the requirement goes live.
  4. Store the recovery codes somewhere that is not the phone holding the authenticator. They are shown once.

Sessions

The same screen lists active sessions with device and location. Revoking one logs that device out immediately. Changing your password ends every other session.

If you lose the authenticator

Recovery codes are the way back in. Without them, recovering the account takes an identity check through support and is deliberately slow.

If you suspect a compromise

In this order:

  1. Kill switch on every account — stops new execution instantly.
  2. Change your password and revoke sessions.
  3. Rotate broker credentials: change the MT password at your broker, revoke cTrader access, delete exchange API keys.
  4. Regenerate webhook URLs and API keys.
  5. Tell support with rough timestamps — the audit log makes the rest reconstructable.
Was this helpful?

Still stuck?

Open a ticket and we will pick it up from your account context.