Security and two-factor authentication

Protect your account with a strong password and 2FA.

A few steps keep your account secure.

Passwords & sign-in

  • Use a strong, unique password, or sign in with Google.
  • Sessions are cookie-based; sign out on shared devices.

Two-factor authentication (2FA)

  • Enable TOTP-based 2FA in Settings — scan the QR code with an authenticator app.
  • Once enabled, every login (password and Google) is challenged for a 6-digit code.
  • 2FA is enforced server-side, so a valid session isn't granted until the code is verified.

“Too many requests” on the code screen

Code entry is limited to 10 attempts every 15 minutes per account, so nobody can sit and guess six digits. Entering the right code clears the count immediately — a few typos on the way in cost you nothing.

  • If you hit the limit, wait for the window to pass and try again; nothing is locked permanently.
  • If your authenticator app's codes are being rejected, its clock has usually drifted — resync the time in the app, or use Email me a code instead.
  • Seeing this without having tried to sign in is worth telling us about — contact us.

“Google hasn't confirmed that email address”

We only accept a Google sign-in when Google itself reports the address as confirmed, because that address is what links the sign-in to your account. If you see this, confirm the address in your Google account, or sign in with your email and password instead — your data is the same account either way.

Ask the support assistant

Answers come from the Help Center articles on this site — it can explain how the app works, not how to trade.

Answers are generated from Help Center articles and can be incomplete. contact us

Still stuck? Tell us what happened, or email support@ledgerofalpha.com.

Security and two-factor authentication — Ledger of Alpha Help