Features Pricing Knowledge base
Start free trial Log in
live feedconnecting
Knowledge baseAccount, billing and referrals

Security: passwords, sessions and logging out everywhere

Password rules, how sessions and cookies work, password reset, login throttling, and what to do if you suspect your account was used by someone else.

Password rules

A password must be at least 10 characters and mix upper and lower case letters with at least one digit. Passwords are stored as scrypt hashes; the platform cannot show you your password, only let you set a new one.

Change it under Account > Security: enter the current password and the new one twice. Changing the password logs out every session, including the one you are using, so sign in again afterwards.

Sessions

Signing in creates a session that lives in the cs_session cookie: HttpOnly, same-site, secure on HTTPS, valid for 30 days. Only a hash of the token is stored on the server. The WebSocket that feeds the app uses the same cookie, so it is authenticated like any page.

Account > Security lists your active sessions with the IP address, browser (user agent) and creation time. Use Log out everywhere to revoke every session, including this one; this is the right move if you used a shared computer or suspect a leaked cookie.

Log out in the top-bar menu ends only the current session.

Forgotten password

Click Forgot password on the login page and enter your email. If the operator has configured outgoing email, you receive a link of the form /reset/<token>; it is single-use and expires. Set a new password on that page. If no email arrives, check spam and then contact support, who can trigger a reset for you.

Login throttling

After 8 failed attempts for the same email from the same IP address within 15 minutes, logins are blocked for 15 minutes with the message Too many attempts. Try again in 15 minutes. This applies to wrong passwords only; successful logins clear the counter.

Form and API protection

Forms carry a CSRF token tied to your session; if a form says Form expired, reload the page and try again. your session changed while the page was open. JSON calls from the app are accepted only from the site's own origin.

Exchange keys and the keyring

Exchange API keys are not protected by your account password. They are encrypted with the separate keyring password you set on the Trading page, which is never stored and never leaves the server's memory for longer than your login session. Someone who obtains your account password still cannot decrypt your keys without the keyring password. See Exchange trading accounts.

If you suspect misuse

  1. Account > Security > Log out everywhere.
  2. Change your password.
  3. On the exchange, delete the API keys you had stored and create new ones; then unlock the keyring and save the new keys.
  4. Review Account > Billing for invoices you did not create and tell support.

Disabled accounts

An operator can disable an account; login then fails with This account is disabled. Contact support. Disabling does not delete data.

Note: the platform never asks for your password, keyring password or exchange secrets by email or chat. Treat any such request as fraud.