> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sellauth.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Account Security

> Two-factor authentication, device sessions, and the settings that protect your shop and its funds.

Your SellAuth account holds your processor credentials, your crypto payout addresses and your order history. Account settings live under [**Account**](https://dash.sellauth.com/user).

## Two-factor authentication

Set up 2FA with an authenticator app. Once enabled, your code is required when you sign in and when you take sensitive actions, including withdrawing crypto and changing your password.

With 2FA off, those actions fall back to a one-time code emailed to you, so the security of your funds rests on the security of your email account.

<Warning>
  Enable 2FA before you connect a payment method or set a crypto payout address. Without a second factor, a leaked password gives an attacker direct access to live payment credentials.
</Warning>

Disabling 2FA also requires a current code, so keep your recovery options for the authenticator app itself somewhere safe.

## Password

Changing your password requires your current password plus your 2FA code, or an emailed one-time code if 2FA is off. You are signed out afterwards and have to sign back in.

## Device sessions

Active sessions are listed under your account, and any of them can be logged out individually, or all at once.

Review the list if you have signed in on a machine you do not control, or if anything looks unfamiliar. Logging out every device is the right first move after a suspected compromise, followed by a password change.

**Remember this device for 30 days** appears when confirming a sensitive action such as a crypto withdrawal. It skips re-authentication on that browser for the period, so leave it unticked on any shared machine.

## API keys

Create API keys under [**Account > Developers**](https://dash.sellauth.com/api). Creating one requires your password and your 2FA code, or an emailed one-time code if 2FA is off.

Each key is scoped twice.

**Access** is either **Full access**, meaning every permission including ones added in future, or **Restricted**, meaning only the permissions you tick.

**Shops** is either **All shops** your account can reach, or only the shops you pick.

Scope every key to what it is for. A key for a stock-sync script needs product permissions on one shop, not full access to everything you own, and a leaked restricted key does far less damage than a leaked full-access one.

The key is shown once, when you create it. After that the dashboard only displays the last few characters, alongside when it was last used. Copy it somewhere safe at creation time.

Keys belong on a server. A key placed in frontend JavaScript, a public repository or a Discord message should be considered compromised. Delete a leaked key and issue a new one.

## Protecting the shop itself

* **Give team members their own logins** with scoped permissions rather than sharing yours. See [Teams and Permissions](/guides/teams-and-permissions).
* **Check Activity Logs** after any staffing change, to see what was done and by whom.
* **Verify crypto payout addresses** when you set them, and again after any suspected compromise. An altered payout address diverts every future payment with no other visible sign.

## Next steps

<CardGroup cols={2}>
  <Card title="Teams and permissions" icon="user-group" href="/guides/teams-and-permissions">
    Scoped access for the people you work with.
  </Card>

  <Card title="Crypto wallets and payouts" icon="wallet" href="/guides/crypto-wallets">
    The authentication required to withdraw.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.