Account Security: Login Passwords and Two-Factor Authentication (2FA)

How to change your login password, enable two-factor authentication, and recover from a temporary account lockout.

Your account is the first line of defense for your resources. We recommend enabling two-factor authentication for every account.

Change your login password

  • If you are signed in, open Settings → Security to change it.
  • If you forgot it, select Forgot password on the sign-in page and reset it through your registered email address.

Note: your account login password and your VPS root password are different credentials. To reset a VPS password, see Forgot Your Password? Resetting Your Login Password and VPS Root Password.

Enable two-factor authentication (2FA)

  • Open Settings → Security.
  • Follow the instructions to scan the QR code with an authenticator app, such as Google Authenticator.
  • Store your recovery codes in a safe place. You will need one to recover access if you lose your phone.

After 2FA is enabled, every sign-in requires both your password and a time-based verification code. A leaked password alone will no longer be enough to access your account.

Is your account locked?

After several consecutive incorrect password attempts, the account is temporarily locked to prevent brute-force attacks. Wait and try again later, or use Forgot password to reset the password immediately.

Additional recommendations

  • Verify your registered email address and keep it accessible. Password resets and important notifications depend on it.
  • Sensitive platform actions, such as destroying a server, require you to enter your password again. This is a normal security safeguard.
  • Protect credentials such as API keys. If one is exposed, revoke it in Settings and issue a replacement immediately.