Your security settings let you manage your password, add an authenticator app, and see which devices are signed in. Open Account > Security to get started.
Set or change your password
Accounts created through Discord may not have a password yet. You can set one from the Password section and then use either your username and password or Discord to sign in.
If a password is already set, enter the current password before choosing a new one. New passwords must contain at least eight characters. Changing your password signs out every existing session, so you will need to sign in again on your other devices.
Enable 2FA
Two-factor authentication uses a six-digit code from an authenticator app. It protects sensitive shop and payout actions even if somebody learns your password. Popbob does not currently ask for this code during sign-in.
- 1
Start setup
In Security, find Two-Factor Authentication and select Enable 2FA.
- 2
Add Popbob to your authenticator
Scan the QR code with your authenticator app. You can also enter the displayed secret key manually. Save that key in a secure place because Popbob does not currently issue separate recovery codes.
- 3
Confirm the setup
Enter the current six-digit code from the app and select Verify and Enable. The code changes regularly, so use the newest one shown in your app.
To disable 2FA later, return to the same page and enter a current authenticator code. If you lose both the authenticator and the saved secret key, contact support for help.
Where 2FA is required
Popbob asks for a 2FA code when you change protected wallet settings. Account balance transfers always require 2FA. A withdrawal also requires it when you use a new or changed payout destination.
Shop ownership transfers use a 2FA code when it is enabled on the current owner's account.
Review active sessions
Active Sessions shows the device, IP address, and last activity for each login. Your current session is labelled Current. Select Revoke beside any other session you do not recognize.
If a session looks unfamiliar, revoke it first and then change your password. Review your shop payout settings as well if the account owns a shop.