> For the complete documentation index, see [llms.txt](https://help.rails.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.rails.xyz/manage-account/account-security.md).

# Account Security

At Rails, the security of your account is our top priority. Click the links below to jump to some common security topics:

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Password Reset</strong></td><td><a href="/pages/mJIamY2bzqDKgII5GZXk#password-reset">/pages/mJIamY2bzqDKgII5GZXk#password-reset</a></td></tr><tr><td align="center"><strong>Single Sign-on (SSO) with Google</strong></td><td><a href="/pages/mJIamY2bzqDKgII5GZXk#single-sign-on-sso-with-google">/pages/mJIamY2bzqDKgII5GZXk#single-sign-on-sso-with-google</a></td></tr><tr><td align="center"><p><strong>Multi-Factor Authentication (MFA)</strong></p><p><br></p></td><td><a href="/pages/mJIamY2bzqDKgII5GZXk#multi-factor-authentication-mfa">/pages/mJIamY2bzqDKgII5GZXk#multi-factor-authentication-mfa</a></td></tr></tbody></table>

{% hint style="danger" %}

#### Security Note

If you suspect unauthorized access to your account, or have urgent sign-in issues, [contact Support immediately](https://railsxyz.zendesk.com/hc/en-us/requests/new).
{% endhint %}

## Password Reset

For your security, use a strong, unique password. Change it if you suspect it has been compromised. You can also change it anytime in account settings, or reset it from the sign-in screen if you forget it.

Click the expandable sections below to see detailed instructions for each method.

<details>

<summary>Reset from <strong>Sign-In Screen</strong></summary>

1. Go to the [sign-in page](https://trade.rails.xyz/trade/BTC-USD).
2. Click on **Forgot Password:**

<figure><img src="/files/NUFyMJkKMNwXiegxDLIW" alt="" width="375"><figcaption></figcaption></figure>

3. Insert the email associated with your account and click **Next**.

<figure><img src="/files/apBnUIUouufZv218YqIG" alt="" width="375"><figcaption></figcaption></figure>

4. Check your email for instructions on resetting your password, then click the **Reset your password** button:

<figure><img src="/files/rDXND62OPHSEHNGTQvK3" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="info" %}
If you do not receive a Password Reset email within 5 minutes, check your spam folder or follow these [troubleshooting tips](/support/troubleshooting-guide.md#manage-account).
{% endhint %}

5. Type in your new password and confirm it in the fields provided and click **Next**.

<figure><img src="/files/pakD9yrLCLfyLKBZJJ3n" alt="" width="375"><figcaption></figcaption></figure>

6. Once successfully changed, you can use your new password to Sign in.

<figure><img src="/files/HFcHmm49KFYX1hqKEKh0" alt="" width="375"><figcaption></figcaption></figure>

</details>

<details>

<summary>Reset from <strong>Settings</strong></summary>

1. [Sign in](https://trade.rails.xyz/trade/BTC-USD) to your Rails account.
2. Click on your user profile at the bottom left of your screen, and select "Security":

<figure><img src="/files/7Fy5JrYU2hPp6qeWIBLy" alt="" width="375"><figcaption></figcaption></figure>

3. Scroll down to the **Password** section, and click the Change button:

<figure><img src="/files/YCzCnhwWqIgz63KN3lAY" alt="" width="563"><figcaption></figcaption></figure>

4. Input your new password in the **New Password** field, re-enter your new password in the **Confirm Password** to confirm it’s accurate, then click the **Update Password** button.<br>

<p align="center"><img src="/files/MVJSDYFx1g6IjdSDC5HU" alt=""></p>

</details>

## Single Sign-On (SSO) with Google

Single Sign-on (SSO) with Google lets you quickly and securely log into your account using your existing Google credentials. Instead of managing a separate username and password, you simply authenticate through your Google account. This adds convenience, enhanced security and a faster login process.

{% hint style="info" %}
Google sign-in uses Google’s MFA protection. Rails does not prompt for email OTP or a passkey during Google sign-in.
{% endhint %}

<details>

<summary>Setting up SSO with Google</summary>

1. Visit the [sign-in page](https://trade.rails.xyz/trade/BTC-USD) and click **Sign in with Google**.

<figure><img src="/files/sCF1oLbORWaVfU4Dl0eo" alt="" width="375"><figcaption></figcaption></figure>

2. Choose the Google account you would like to sign in with.

<figure><img src="/files/EyTTDGMT5KXReFHaO7T9" alt="" width="375"><figcaption></figcaption></figure>

You should now be logged in and navigated to your Rails account automatically. If you're having issues, ensure the email is the one associated with your Rails account or check out our [troubleshooting tips](/support/troubleshooting-guide.md).

</details>

## Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) adds an extra layer of protection to your login process by requiring more than just your password. With MFA enabled, you’ll be asked to verify your identity using an additional factor from the following options:

### **One-Time Passcode (OTP)**

An OTP is a short, temporary security code we email you before you sign in. Each OTP is valid for a single use and expires within 10 minutes, helping to ensure that only you can access your account.

<details>

<summary>Setting up OTP</summary>

Complete the following steps to set up an OTP on your account:

1. Click on the **Options button** (your username) on the top right of the trading page, then click **Settings**.

<figure><img src="/files/NNTHqI6ko0Zpvr5ZbCJV" alt="" width="563"><figcaption></figcaption></figure>

2. You will automatically be directed to the Security page. Select **Multi-Factor Authentication**.

<figure><img src="/files/mR6OurcOh27rt7KSV2Kl" alt="" width="563"><figcaption></figcaption></figure>

3. Click the **toggle switch** to enable OTP. It will move to the right and become blue when enabled.

<figure><img src="/files/96qBMRvLohI41xYunPOa" alt="" width="563"><figcaption></figcaption></figure>

If you wish to disable OTP at any point, click the toggle switch again until it is left aligned.

</details>

<details>

<summary>Signing in using OTP</summary>

1. Go to the [sign-in page](https://trade.rails.xyz/trade/BTC-USD).

{% hint style="info" %}
You will not be asked to complete OTP if you [Sign in with Google](#single-sign-on-sso-with-google), even if it's enabled.
{% endhint %}

2. Input your email and password and click **Sign In.**<br>

   <figure><img src="/files/bauXuRoKRPWpm3UQPMlW" alt=""><figcaption></figcaption></figure>
3. If you have both OTP and passkeys enabled, you will be prompted to select between the two verification methods. Ensure the OTP option is selected then click **Sign In**.

<figure><img src="/files/BknOcuUeFfxq7cEYewY1" alt="" width="375"><figcaption></figcaption></figure>

4. You will be prompted to input the code. Check your email for a unique passcode as displayed below.

<figure><img src="/files/CfUngjge9rpbAwy6xKuy" alt="" width="375"><figcaption></figcaption></figure>

5. Navigate back to the sign in screen, input the code and click **Sign in**.<br>

   <figure><img src="/files/s17lIDaQrsFok9GAF4IA" alt=""><figcaption></figcaption></figure>

If successful, you will be directed to Rails' main trading page.

{% hint style="warning" %}
Check out our [troubleshooting tips](/support/troubleshooting-guide.md#manage-account) if you are having trouble logging in.
{% endhint %}

</details>

### **Passkeys**

Passkeys are secure digital credentials stored on your device, offering an extra security layer for your account. They use advanced encryption and biometric verification (e.g., Face ID, fingerprint) or a device PIN for quick and secure identity verification. Physical security keys like YubiKey can also be used as passkeys to enhance security.

<details>

<summary>Setting up a Passkey</summary>

1. Click on your profile in the bottom left corner, and navigate to the **Security** area of your account:

<figure><img src="/files/2WeiAaUuUHGrHNz6QRvD" alt="" width="563"><figcaption></figcaption></figure>

2. Select the **Create Passkey** button:

<figure><img src="/files/l4raR1J2U7STqc41Djws" alt="" width="563"><figcaption></figcaption></figure>

3. Your device may suggest a specific passkey method (e.g. 1Password, iCloud, etc.) based on what you have available. Follow the prompts to set up the suggested passkey, or click **X** or **Cancel** until you get a screen similar to the below screenshot to select your preferred passkey method.

<figure><img src="/files/UsjH7Zz8nIEMUZKhdFTO" alt="" width="375"><figcaption></figcaption></figure>

5. Follow the verification prompts on your device, or jump to [supported passkeys](#supported-passkeys) to see steps for specific, common passkeys.
6. Once completed, you should see your passkey listed in your settings page as shown below.
   1. Ensure the toggle for **Passkeys** is on. It will be blue and switched to the right.
   2. To add additional passkeys, simply click the **Add Passkey** button in the bottom left corner and repeat this process.

<figure><img src="/files/JaXjAAkqUaVyHFKyDUhc" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="success" %}
Edit your passkey names for easier identification by clicking the pencil icon <img src="/files/HDQiwSRfEvC1qGxf1KsA" alt="" data-size="line"> in the Action column.
{% endhint %}

</details>

<details>

<summary>Signing in using Passkeys</summary>

1. Go to the [sign-in page](https://trade.rails.xyz/trade/BTC-USD), enter your email and password and click Sign In.

{% hint style="info" %}
You will not be asked to verify via passkey if you [Sign in with Google](#single-sign-on-sso-with-google), even if it's enabled.
{% endhint %}

2. If you have passkeys enabled, you will be prompted to use that passkey:

<figure><img src="/files/WJQEu0nn0tWBBnLvhwCE" alt="" width="563"><figcaption></figcaption></figure>

3. Follow the prompts on your passkey. If successful, you will be directed to Rails' main trading page.<br>

If you are having issues using your passkey, you can have a one-time passcode sent to you by email instead:

<figure><img src="/files/wybm9Wu8HuXRof4XLRru" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="warning" %}
Check out our [troubleshooting tips](/support/troubleshooting-guide.md#manage-account) if you are having trouble logging in.
{% endhint %}

</details>

#### Supported Passkeys

Rails supports a broad list of secure FIDO2-based passkeys for MFA. FIDO2 passkeys are secure digital credentials stored directly on your device. They use cryptographic keys paired with biometric verification (like fingerprint or facial recognition) or a PIN. Because passkeys are device-bound, they’re significantly more resistant to common cyber threats like phishing, credential theft, and password reuse attacks.

#### Setting up Common Passkeys

If you have multiple passkey options on your device, it will decide the hierarchy of which one you are presented with first. Click **X** or **Cancel** when prompted if you wish to use or set up a different passkey.

Step-by-step instructions on how to set up some of the most common passkeys can be found in the expandable sections below:

<details>

<summary>iCloud Keychain</summary>

Mac users that utilize biometric (fingerprint) scan set up access to their passkey by using the following steps:

1. Your device may prompt you to setup a different passkey (e.g. Chrome, 1Password, etc.) proactively. Click **X** or **Cancel** until you get to the following screen, then select **iCloud Keychain**.
2. Use your fingerprint to allow for a passkey to be saved on your iCloud Keychain.
3. If saved successfully, this passkey will be saved in your security settings under passkeys as *iCloud Keychain*.

<figure><img src="/files/eTAxJj7Fyr8sANVPAOCK" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="info" %}
Click the pencil icon to edit the passkey name if you're adding multiple passkeys or devices.
{% endhint %}

</details>

<details>

<summary>1Password</summary>

Users who have the 1Password browser extension are able to use their 1Password account to securely store their passkey by following these steps:

1. Unlock your 1Password account (if prompted).

<figure><img src="/files/ryVlY7NhQriWYPOrH3vc" alt="" width="563"><figcaption></figcaption></figure>

2. Click New Item on the 1Password prompt and then click Save.

<figure><img src="/files/dTP5fqmin5MfviAFMd1c" alt="" width="563"><figcaption></figcaption></figure>

3. Your passkey is automatically created in 1Password and if successful, it will be listed in Settings > Security > MFA > Passkeys as *1Password*.

{% hint style="info" %}
Click the pencil icon to edit the passkey name if you're adding multiple passkeys or devices.
{% endhint %}

</details>

<details>

<summary>Chrome Profile</summary>

Users who have biometrics set up in their Chrome browser can also use this as a passkey method.

1. Your device may prompt you to setup a different passkey (e.g. iCloud, 1Password, etc.) proactively. Click **X** or **Cancel** until you get to the following screen, then select **Your Chrome profile**.
2. Ensure the right profile is selected and click **Continue.**
3. Provide biometric scan or password to continue.
4. If saved successfully, this passkey will be saved in Settings > Security > MFA > Passkeys. as *Chrome on Mac.*

<figure><img src="/files/2W4b0x7WmiJ335CQnusM" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="info" %}
Click the pencil icon to edit the passkey name if you're adding multiple passkeys or devices.
{% endhint %}

</details>

<details>

<summary>Device QR Code or Security Key</summary>

Users are able to access their passkey by using another device or private security key by using the following steps:

1. Your device may prompt you to setup a different passkey (e.g. iCloud, 1Password, etc.) proactively. Click **X** or **Cancel** until you get to the following screen, then select **Use phone, tablet or Security Key.**

<figure><img src="/files/YdRb9e8BmPBtPxGRG4vi" alt="" width="375"><figcaption></figcaption></figure>

2. When presented with this screen, you can choose to either use a camera on another device to scan the QR Code or insert and touch your security key to set up the passkey.

<figure><img src="/files/TcRvMlLgI9AyGpeRpL7P" alt="" width="375"><figcaption></figcaption></figure>

3. Follow the prompts on your device.
4. If saved successfully, this passkey will be visible in your passkey list in Settings > Security > MFA > Passkeys.

</details>
