Passwords, 2FA and staying signed in
This account can see your bank data, so it deserves better security than your average login. Here is everything you can turn on.
Password and email
Both live under Profile & Security in the user menu. Changing your password asks for the current one first; changing your email sends a verification to the new address before it takes over, so a typo cannot lock you out. New accounts also verify their email before the first sign-in works at all, which is why an unverified signup sees a resend prompt rather than a dashboard.
Two-factor authentication
The Multi-Factor Authentication (MFA) card sets up TOTP with any authenticator app: scan the QR code, enter the six-digit code, done. From then on, sign-in asks for a code after your password, on the web and in the mobile apps alike, unless you ticked Remember this device for 7 days at the last prompt, which spares your own machines the ritual for a week at a time.
- Setup ends with a set of backup codes, shown once. Store them somewhere that is not the phone running your authenticator; they are the way back in if that phone is lost.
- Backup codes can be regenerated later, with your password. Regenerating invalidates every previous code, which is exactly what you want after using one.
Turn it on
Staying signed in
The login page offers Keep me signed in for 30 days. It is off by default; sessions on a shared or borrowed machine should be short, and opting into a long one is a decision, not a surprise. Tick it on your own devices and the daily sign-in disappears. The 30 days are enforced on our servers, not just in your browser, and repeated failed sign-in attempts are blocked temporarily as automated guessing protection.
What next
On the phone, the same account adds Face ID or fingerprint unlock; the mobile security guide covers it. And remember that bank connections never involve your banking passwords at all; that is the point of open banking.
