Account Security Settings

Change your password, set up two-factor authentication, and manage login sessions

Your security settings are located in the Security tab of your Profile page.

Changing Your Password

  1. Go to Profile → Security
  2. Click Change Password
  3. Enter your current password
  4. Enter your new password (minimum 8 characters) — a strength meter shows the rating from "Very Weak" to "Strong" based on length and character variety
  5. Confirm your new password
  6. Click Update Password

Depending on your account settings, you may be asked to enter a 6-digit verification code sent to your email before the change takes effect. The code expires after 10 minutes.

Password Strength Tips

The strength meter evaluates:

  • Length — longer is better (8+, 12+, 16+ characters improve the rating)
  • Character variety — mixing lowercase, uppercase, numbers, and symbols increases strength
  • The meter provides specific feedback like "Try adding uppercase letters" or "Try adding symbols"

Password Reset

If you've forgotten your password:

  1. Go to the Forgot Password page (also linked from the login page)
  2. Enter your email address
  3. Check your email for a reset link and verification code
  4. You can either click the link in the email or enter the 6-digit code on the next screen
  5. Set a new password

The confirmation page auto-redirects after a short countdown. For security, the page always shows a success message regardless of whether the email exists (to prevent email enumeration).

Two-Factor Authentication (2FA)

Two-factor authentication adds a second step to login by requiring a time-based code from an authenticator app.

Setting Up 2FA

  1. Go to Profile → Security
  2. Click Enable Two-Factor Authentication
  3. A QR code appears — scan it with your authenticator app (Google Authenticator, Authy, 1Password, etc.). If you can't scan the QR code, expand the manual entry section to copy the secret key.
  4. Enter the 6-digit code from your authenticator app to verify the setup
  5. You'll be shown 8 single-use backup codes — save these somewhere safe

Saving Your Backup Codes

After enabling 2FA, you'll receive 8 backup codes. You can:

  • Copy all to your clipboard
  • Download as a text file

Each backup code can only be used once. These are your fallback if you lose access to your authenticator app.

Logging In with 2FA

When 2FA is enabled:

  1. Enter your email and password as usual
  2. Enter the 6-digit code from your authenticator app
  3. Optionally check "Trust this device" to skip 2FA for 30 days on that device

You can also use a backup code instead of the authenticator code.

Regenerating Backup Codes

If you've used most of your backup codes or lost them:

  1. Go to Profile → Security
  2. Click Regenerate Backup Codes
  3. Enter a current 6-digit code from your authenticator app to confirm
  4. New codes are generated — save them immediately (the old codes are invalidated)

Disabling 2FA

  1. Go to Profile → Security
  2. Click Disable Two-Factor Authentication
  3. Enter your account password to confirm
  4. 2FA is removed and you'll be logged out

Login Methods

Your account supports multiple login methods:

  • Email + Password — the standard method
  • OTP (One-Time Password) — a 6-digit code sent to your email for passwordless login
  • Social Login — sign in via Discord, GitHub, or Google (managed in the Connected tab)

All login methods go through bot verification and, if enabled, two-factor authentication.

Account Information

The Security tab also displays read-only account details:

  • Client ID — your account number
  • Account Status — Active, Suspended, etc.
  • Member Since — when your account was created
  • Credit Balance — available account credit

Best Practices

  • Use a unique password not shared with other sites
  • Enable 2FA — it's the single most effective way to protect your account
  • Save your backup codes offline, not on the same device as your authenticator
  • Review your connected accounts periodically and disconnect any you no longer use
  • If you suspect unauthorized access, change your password immediately and contact support