Security & 2FA
Protect user accounts with two-factor authentication and secure password management.
Overview
CoinTrail provides robust security features to protect user accounts, including two-factor authentication (2FA), session management, and login activity monitoring.
Security Features
- Two-Factor Auth - TOTP-based 2FA using authenticator apps
- Recovery Codes - Backup codes for account recovery
- Secure Passwords - Bcrypt hashing with minimum requirements
- Password Reset - Secure email-based password recovery
Two-Factor Authentication (2FA)
Two-factor authentication adds an extra security layer by requiring a time-based code from your phone in addition to your password.
Supported Authenticator Apps
- Google Authenticator - iOS and Android
- Microsoft Authenticator - Feature-rich with backup options
- Authy - Cross-device sync and encrypted backups
- Any TOTP App - Any app supporting TOTP standard
Enabling 2FA
- Go to Profile Menu > Security or visit
/user/security - Click Enable Two-Factor Authentication
- Scan the QR code with your authenticator app
- Enter the 6-digit verification code
- Download and securely store your recovery codes
Store Recovery Codes Safely
Each recovery code can only be used once. Store them in a secure location. If you lose your authenticator and all recovery codes, you may lose access to your account.
Disabling 2FA
- Go to Security Settings at
/user/security - Click "Disable 2FA"
- Enter your password to confirm
Password Security
Password Requirements
CoinTrail enforces strong password requirements:
- Minimum 8 characters
- At least one uppercase letter
- At least one lowercase letter
- At least one number
- Special characters recommended
Changing Password
- Go to your Profile page and select the Password tab
- Enter your current password
- Enter your new password
- Click Change Password to save
Account Recovery
Lost Password
- Go to login page and click "Forgot Password"
- Enter your email address
- Check email for reset link (valid 60 minutes)
- Click link and create new password
Lost 2FA Access
- Use one of your saved recovery codes at login
- Once logged in, disable 2FA in Security Settings
- Set up 2FA again with your new device and save new recovery codes
Prevention is Key
Store recovery codes securely, use apps with cloud backup like Authy, and keep your email account secure.