> ## Documentation Index
> Fetch the complete documentation index at: https://developers.uqpay.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> The merchant dashboard Settings > Security page — centrally manage account security: change your login password, two-factor authentication (authenticator app / SMS), passkeys, recovery email, bind a phone number, and view and sign out active sessions.

## What this is

This is the **Security** page under **Settings** in the merchant dashboard (page title "Security", subtitle "Manage your account security settings"), reached from Settings. It centralizes all of your account's security settings — here you can: change your login password, enable/manage two-factor authentication (authenticator app or SMS), add a passkey, set a recovery email, bind or change your phone number, and view which devices are currently signed in and sign out suspicious sessions. Come here to harden your account, change your password, turn on two-factor authentication, or kick another device offline.

At the top of the page is an **account security overview** that scores "{X}/3 security checks passed" based on whether you've enabled two-factor authentication, added a passkey, and verified a recovery email — with suggestions for improvement if you're not at a perfect score.

## Steps

**Change your password:**

1. In the **Authentication** section, click **Change Password** on the "Password" row.
2. Fill in **Current Password**, **New Password**, and **Confirm New Password** in order; if two-factor authentication is already enabled, you'll also need an **Authenticator Code** field (6 digits).
3. Click **Update Password**. On success you'll see "Password changed successfully. Please sign in again." and be signed out automatically — sign back in with the new password.

**Enable two-factor authentication (authenticator app):**

1. In the **Two-Factor Authentication** section, click **Set Up 2FA**.
2. **Scan the QR code** with an authenticator app on your phone (e.g. Google Authenticator, Microsoft Authenticator, 1Password, Authy); if you can't scan it, click "Or enter this key manually" to copy the key instead. If you don't have an app yet, the dialog includes download links for a few common ones.
3. Click **Next**, enter the **6-digit code** shown in the app, then click **Enable 2FA**.
4. The system then shows a set of **Recovery Codes** — shown only this once. Immediately click **Copy** or **Download** to save them somewhere safe, then click **Done**.

**Enable SMS verification (requires a bound, verified phone number and 2FA already on):** turn on the toggle on the "SMS verification" row in the **Two-Factor Authentication** section. If you haven't bound a verified phone number yet, you'll be prompted to bind one first.

**Manage an enabled authenticator** (via the "..." menu on the right of the "Authenticator App" row):

* **View Recovery Codes**: enter your authenticator's 6-digit code to view your current recovery codes.
* **Update Authenticator**: re-bind the authenticator to a new device when you get a new phone — verify your identity first, then scan the new QR code; the old codes stop working.
* **Disable 2FA**: turn off two-factor authentication — requires verifying your identity via the authenticator first.

**Add a passkey:**

1. In the **Passkeys** section, click **Add Passkey**.
2. Give the passkey a name (e.g. "MacBook Touch ID"), click **Register Passkey**.
3. Follow the browser's prompt to complete fingerprint / face / security-key verification. Added passkeys can be **Rename**d or **Remove**d via the "..." menu.

**Set a recovery email:**

1. In the **Recovery email** section, click **Add email**, enter an address different from your primary login email, and click **Add email**.
2. The system sends a verification link to that address — the email shows **Pending verification** until you click the link, after which it becomes **Verified**. To remove it, click **Remove** on that email's row.

**Bind / change your phone number:** on the "Phone number" row in the **Authentication** section, click **Set up** (unbound) or **Change** (already bound), enter the number in the dialog, send the verification code, and submit after entering the 6-digit code you receive.

**View and sign out sessions:** the **Active Sessions** section shows every device currently signed in. Click **Revoke** on a non-current session to sign that device out; click **Sign Out All** in the top-right and enter your password to sign out every session except the current device at once.

## Fields and statuses

**Account security overview:**

| Field / State                         | Meaning (merchant view)                                                                                                      |
| ------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| {X}/3 security checks passed          | Number of completed security items, out of a max of 3 (two-factor authentication, passkey, recovery email each count as one) |
| Your account security is strong       | All three security checks passed                                                                                             |
| Your account security can be improved | One or more security items are still incomplete — improve per the suggestions shown                                          |
| Security Recommendations              | Shown when two-factor authentication isn't enabled, suggesting "Enable two-factor authentication for added security"         |

**Phone number status:**

| Status    | Meaning                                                                               |
| --------- | ------------------------------------------------------------------------------------- |
| Verified  | Phone number is bound and verified — usable for account recovery and SMS verification |
| Not bound | No phone number bound yet                                                             |

**Two-factor authentication:**

| Field / State     | Meaning                                                                                                |
| ----------------- | ------------------------------------------------------------------------------------------------------ |
| Authenticator App | Generates a 6-digit code via a TOTP app like Google Authenticator or Authy                             |
| SMS verification  | Receive a 6-digit code via SMS as a second verification factor                                         |
| Active            | This verification method is enabled and in effect                                                      |
| 2FA is not set up | No two-factor authentication method is enabled yet                                                     |
| Recovery Codes    | One-time backup codes used to sign in when you can't use the authenticator; each can only be used once |

**Passkeys:**

| Field / State       | Meaning                                                                                       |
| ------------------- | --------------------------------------------------------------------------------------------- |
| Built-in / External | Passkey type: Built-in = the device's own (fingerprint/face), External = a security key, etc. |
| Added               | The date this passkey was added                                                               |
| Last used           | The most recent time this passkey was used                                                    |
| Synced              | This passkey is synced across multiple devices                                                |

**Recovery email:**

| Field / State        | Meaning                                                                               |
| -------------------- | ------------------------------------------------------------------------------------- |
| Primary login email  | Your primary login email, locked and cannot be removed                                |
| Verified             | The recovery email has been verified via the email link and is active                 |
| Pending verification | The recovery email has been entered but the verification link hasn't been clicked yet |

**Active Sessions:**

| Field / State | Meaning                                                                                                      |
| ------------- | ------------------------------------------------------------------------------------------------------------ |
| Current       | The session you're using right now                                                                           |
| Location / IP | The geographic location and IP address of that session (shows "Unknown" if the location can't be determined) |
| Last active   | The most recent activity time of that session                                                                |

## Edge cases and troubleshooting

* **Signed out after changing password**: this is expected security behavior — sign back in with the new password.
* **Changing password asks for an authenticator code**: two-factor authentication is enabled on your account, so changing your password also requires the 6-digit authenticator code.
* **Recovery codes are only shown once**: the recovery codes shown right after enabling 2FA won't be fully displayed again — copy or download them on the spot; afterward you can retrieve them again via "View Recovery Codes".
* **Got a new phone, lost the authenticator**: use "Update Authenticator" to re-bind the authenticator to the new device; if the old authenticator is completely unusable, sign in with a saved recovery code and set it up again.
* **The SMS verification toggle won't turn on / asks to bind a phone first**: SMS verification requires a verified phone number — bind one on the "Phone number" row first, then enable it.
* **Can't turn off SMS verification**: when SMS is your only second factor, it can't be disabled — enable another method (e.g. authenticator) first, then turn off SMS.
* **Recovery email stuck on "Pending verification"**: the verification link hasn't been clicked yet — go check that inbox and click the link; each account can only have one recovery email, which must differ from your primary login email.
* **See an unfamiliar login session**: click **Revoke** on that session to sign it out immediately, then change your password and enable two-factor authentication as soon as possible.
* **Passkey registration fails**: usually the browser's biometric prompt was canceled or the device doesn't support it — retry and follow the browser's prompt to complete fingerprint/face verification.

## Common questions (Q\&A)

* **Q: Where do I change my login password?** A: Settings > Security > click **Change Password** on the "Password" row, fill in current and new password; you'll be asked to sign in again with the new password afterward.
* **Q: Why does changing my password sign me out?** A: This is expected security behavior — you'll be signed out automatically once the password change succeeds; sign back in with the new password.
* **Q: How do I enable two-factor authentication?** A: On the Security page, click **Set Up 2FA** in the **Two-Factor Authentication** section, scan the QR code with an authenticator app, enter the 6-digit code to enable it, and save your recovery codes.
* **Q: Which authenticator app should I use?** A: Any TOTP app works — Google Authenticator, Microsoft Authenticator, 1Password, Authy, etc.; the setup dialog also has download links.
* **Q: Can I get codes by SMS?** A: Yes — turn on "SMS verification" under **Two-Factor Authentication**, provided you already have a bound, verified phone number.
* **Q: What are recovery codes? What if I lose them?** A: Recovery codes are one-time backup codes used to sign in when you can't use your authenticator; you can view them again via "View Recovery Codes" in the "Authenticator App" row's "..." menu.
* **Q: I got a new phone — how do I migrate the authenticator?** A: Click "Update Authenticator" in the "Authenticator App" row's "..." menu, verify your identity, then scan the new QR code on the new device — the old code becomes invalid.
* **Q: How do I turn off two-factor authentication?** A: Click "Disable 2FA" in the "Authenticator App" row's "..." menu and confirm your identity as prompted; disabling it reduces your account's security.
* **Q: What's a passkey? How do I add one?** A: A passkey lets you sign in with your fingerprint, face, or a security key instead of a password; click **Add Passkey** in the **Passkeys** section, name it, and follow the browser's prompt to complete biometric verification.
* **Q: What's a recovery email for? How do I set it?** A: It's used for account recovery and security alerts; click **Add email** in the **Recovery email** section with an address different from your primary email, then verify via the link sent to it.
* **Q: Can I delete my primary email?** A: No — the primary login email is locked; you can only add/remove extra recovery emails.
* **Q: How do I see which devices I'm signed in on?** A: The **Active Sessions** section on the Security page lists every signed-in device's browser, OS, location, IP, and last active time.
* **Q: How do I kick other devices offline?** A: Click **Revoke** on a single session, or click **Sign Out All** and enter your password to sign out every session except the current device at once.
* **Q: What should I do if I suspect my account was compromised?** A: First revoke suspicious sessions under **Active Sessions** or click **Sign Out All**, then change your password and enable two-factor authentication to harden your account.
* **Q: How is the account security overview score calculated?** A: Based on whether you've enabled two-factor authentication, added a passkey, and verified a recovery email — one point per item completed, out of a maximum of 3.
* **Q: How do I bind or change my phone number?** A: On the "Phone number" row in the **Authentication** section, click **Set up** or **Change**, enter the number, and submit after entering the 6-digit code you receive.
