Skip to main content

Account security

Enrolling a second factor, recovery codes, the actions that ask you to confirm again, and active sessions.

Sign-in is passwordless: a link to your inbox, and optionally a second factor. Everything you can change about that, and about the devices signed in to your account, is in Settings under Security.

Two-factor authentication

Enable it in Settings and scan the code with an authenticator app — Google Authenticator, 1Password, Authy and Bitwarden all work. You confirm the enrolment by typing the first six-digit code, and from then on you are asked for one at sign-in.

What it protects is the gap a magic link leaves. Clicking the link proves you hold the mailbox and nothing else; with an authenticator enrolled, the link alone no longer reaches the app. Sign-in stops at /verify-2fa until a code clears.

That wall is checked on every entry to the app, not once when the link is clicked. Navigating straight to a page inside the app does not step around it, and there is no option to remember a device — a device is not a second factor, so it cannot stand in for one.

Disabling two-factor authentication asks for a fresh code from the authenticator you are removing, and signs out every other session as it completes.

Recovery codes

You get ten codes, each three groups of four characters. They are generated in your browser and shown once, with Copy and Download buttons — Trepeat stores only their hashes and cannot show them again.

They are set before you first reach the app, not when you enable two-factor authentication, and enabling it later does not replace them. They are the account-recovery factor for the whole account, which is why they exist even if you never enrol an authenticator.

  • Each code is single-use. Settings shows how many of the ten are unused, warns below four, and warns harder at zero.
  • Regenerating replaces the whole set. Any unused codes from the old set stop working. It requires a fresh authenticator code, or — if you have no authenticator — one unused code from the current set. All other sessions are signed out once you confirm you have saved the new ones.
  • A code is the only way past the sign-in wall. Redeeming one at /verify-2fa also removes the enrolled authenticator in the same step, so you re-enrol afterwards if you want the factor back.

Actions that ask you to confirm again

Some actions ask for a six-digit code even though you are already signed in. Sessions are not time-boxed, so being at two-factor level only proves a code was typed at some point — it cannot authorise something irreversible weeks later. These actions want one typed in the last five minutes, and the check runs on the server: the dialog is how you are asked, not what decides.

  • Deleting your Trepeat account.
  • Opening the billing portal, buying an extra account slot, or removing one.
  • Regenerating recovery codes.
  • Disabling two-factor authentication.
  • Changing your sign-in email.

If you have no authenticator enrolled there is no second factor to re-confirm, so deleting the account and the billing actions proceed directly. Regenerating codes and changing the sign-in email still ask, and accept an unused recovery code instead. Slots and plans are covered in Plans, slots and trials.

Changing or removing a backup email is asked for differently, and it is worth being exact rather than lumping it in with the list above. Setting your first backup email does not ask at all. Changing or removing one asks for a code if you have an authenticator, and proceeds directly if you do not — because there is no second factor to challenge, and a prompt that verified nothing would only look like protection. Unlike the actions above, this confirmation is asked for in the browser rather than checked again by the server, so treat it as a guard against a mis-click rather than against someone holding your session. Keeping the address current still matters: it is the channel account recovery uses.

Active sessions

The panel lists every device currently signed in, each row showing the browser and system read from its user agent, the IP it connected from, and when it was last active. It refreshes while the tab is open, so a sign-in elsewhere appears without reloading.

Sign out one row, or use Sign out all other sessions to clear everything except the one you are using. Signing out the session you are on returns you to the sign-in page. Nothing expires on a timer, so sessions accumulate until they are signed out — past five, the panel shows the count and scrolls.

Below it, Recent activity is the full security-event history for your account — sign-ins, factor changes, code regenerations, session revocations — loaded ten at a time as you scroll, and updated across your other open tabs as events land.

What Trepeat holds for a broker connection

A MetaTrader account is stored as its number, its server name, and its trading password held encrypted in the database vault. The password is never shown again after you enter it and is used only to open the broker connection. Deleting the account removes the stored credential with it. See Connecting a MetaTrader account.

cTrader holds no password at all. You authorise Trepeat on cTrader's own site, and the authorisation that comes back is what is encrypted and kept — against the cTrader ID rather than against a single account, because one authorisation can cover several. Withdrawing it in cTrader ends Trepeat's access, and deleting your Trepeat account destroys it too. See Connecting a cTrader account.