Secure your account
Your account controls your website, your customers' data and your money. A few minutes of setup makes it dramatically harder for anyone else to get in.
Step by step
- 1
Turn on two-factor authentication
In Settings → Security, enable two-factor authentication with an authenticator app. Save your one-time recovery codes somewhere safe in case you lose your phone.
- 2
Review your sign-ins
Check the recent sign-ins list. If you don't recognise one, change your password — every other device gets signed out.
- 3
Give the right access
If you have a team, invite them with the least access they need. Roles are enforced, so a viewer can't change what only an admin should.
- 4
Know your safety nets
Sensitive actions ask you to confirm it's you (step-up), and security emails alert you to password, 2FA and new-device events — so account takeover is visible, not silent.
Your checklist
0/5 doneBest practices
- ✓ Use an authenticator app rather than SMS — it's stronger and not tied to your phone number.
- ✓ Store your recovery codes offline, not in the same place as your password.
- ✓ Give each team member only the access their job needs.
Common mistakes
- ✕ Skipping 2FA because it feels like a hassle — it's the single biggest protection.
- ✕ Sharing one login across a team instead of inviting members with roles.