Account security and two-factor authentication
Content updated on
Security basics
TableTransfers passwords are stored hashed (we cannot see your password). Sessions expire after 30 days of inactivity. We do not allow sign-in from password lists known to be exposed in public data breaches — if your password appears in such a list, you’ll be prompted to change it on next sign-in.
Enabling two-factor authentication
We strongly recommend 2FA for any account associated with a marketplace listing or a paid subscription.
- Sign in and visit Account → Security
- Click Enable 2FA
- Scan the QR code with any TOTP authenticator (1Password, Authy, Google Authenticator)
- Enter the six-digit code to confirm
Recovery codes
After enabling 2FA, you’ll be given ten one-time recovery codes. Store these somewhere safe — a password manager is ideal. If you lose access to both your 2FA device and your recovery codes, you can recover your account by emailing [email protected] and providing identity verification.
What to do if your account is compromised
Email [email protected] immediately. We can lock the account and walk you through recovery.