Securing your account
Practical steps to keep your balance and API access safe — passwords, sessions, keys — and what we do on our side.
- Last updated
- Updated
- Reading time
- 1 min read
On this page7
Your account holds a balance and can create API keys, so it's worth a few minutes of care.
Use a strong, unique password
Eight characters is the minimum; a long passphrase kept in a password manager is far better. Don't reuse a password from another site — when sites leak passwords, attackers try them everywhere else.
Note
Two-factor sign-in isn't available yet. Until it is, a unique password is your most important protection.
Know how sessions work
- Signing in keeps that browser signed in for 30 days, extended each time you come back.
- Changing your password signs out every other session. Use it as "sign out everywhere" if you think someone else has access.
- Resetting your password by email signs out every session, including the one you're using.
Keep API keys on your server
API keys can spend your balance. API keys and key security covers storing, rotating and revoking them.
Watch your ledger
Every charge appears in your ledger. Orders you don't recognise are the first sign of a leaked key or password.
What we do on our side
- Passwords are stored only as scrypt hashes, never in plain text.
- Session tokens and API keys are stored only as SHA-256 hashes.
- Sign-in, sign-up and password-reset attempts are rate limited.
- Card payments go through Stripe; we never see your card number.
Phishing
We'll never ask for your password, an API key or a webhook secret — by email, chat or phone. Password-reset emails only ever link to passcode.sh.
Think your account is compromised?
- Change your password. That signs out every other session.
- Revoke your API keys on the API keys page and create new ones.
- Rotate your webhook signing secret in Settings.
- Email support@passcode.sh and tell us what you've seen.