Account Security: Login Passwords and Two-Factor Authentication (2FA)
How to change your login password, enable two-factor authentication, and recover from a temporary account lockout.
Your account is the first line of defense for your resources. We recommend enabling two-factor authentication for every account.
Change your login password
- If you are signed in, open Settings → Security to change it.
- If you forgot it, select Forgot password on the sign-in page and reset it through your registered email address.
Note: your account login password and your VPS root password are different credentials. To reset a VPS password, see Forgot Your Password? Resetting Your Login Password and VPS Root Password.
Enable two-factor authentication (2FA)
- Open Settings → Security.
- Follow the instructions to scan the QR code with an authenticator app, such as Google Authenticator.
- Store your recovery codes in a safe place. You will need one to recover access if you lose your phone.
After 2FA is enabled, every sign-in requires both your password and a time-based verification code. A leaked password alone will no longer be enough to access your account.
Is your account locked?
After several consecutive incorrect password attempts, the account is temporarily locked to prevent brute-force attacks. Wait and try again later, or use Forgot password to reset the password immediately.
Additional recommendations
- Verify your registered email address and keep it accessible. Password resets and important notifications depend on it.
- Sensitive platform actions, such as destroying a server, require you to enter your password again. This is a normal security safeguard.
- Protect credentials such as API keys. If one is exposed, revoke it in Settings and issue a replacement immediately.