Account Security
At Rails, the security of your account is our top priority. Click the links below to jump to some common security topics:
Security Note
If you suspect unauthorized access to your account, or have urgent sign-in issues, contact Support immediately.
Password Reset
For your security, use a strong, unique password. Change it if you suspect it has been compromised. You can also change it anytime in account settings, or reset it from the sign-in screen if you forget it.
Click the expandable sections below to see detailed instructions for each method.
Reset from Sign-In Screen
Go to the sign-in page.
Click on Forgot Password:

Insert the email associated with your account and click Next.

Check your email for instructions on resetting your password.

If you do not receive a Password Reset email within 5 minutes, check your spam folder or follow these troubleshooting tips.
Click on Reset your password in the email.

Type in your new password and confirm it in the fields provided and click Next.

Once successfully changed, you can use your new password to Sign in.

Reset from Settings
Sign in to your Rails account.
Click on your user profile at the bottom left of your screen, and select "Security":

Scroll down to the Password section, and click the Change button:

Input your new password in the New Password field.
Re-enter your new password in the Confirm Password to confirm it’s accurate.

Click Update Password.
Single Sign-On (SSO) with Google
Single Sign-on (SSO) with Google lets you quickly and securely log into your account using your existing Google credentials. Instead of managing a separate username and password, you simply authenticate through your Google account. This adds convenience, enhanced security and a faster login process.
Google sign-in uses Google’s MFA protection. Rails does not prompt for email OTP or a passkey during Google sign-in.
Setting up SSO with Google
Visit the sign-in page and click Sign in with Google.

Choose the Google account you would like to sign in with.

You should now be logged in and navigated to your Rails account automatically. If you're having issues, ensure the email is the one associated with your Rails account or check out our troubleshooting tips.
Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) adds an extra layer of protection to your login process by requiring more than just your password. With MFA enabled, you’ll be asked to verify your identity using an additional factor from the following options:
One-Time Passcode (OTP)
An OTP is a short, temporary security code we email you before you sign in. Each OTP is valid for a single use and expires within 10 minutes, helping to ensure that only you can access your account.
Setting up OTP
Complete the following steps to set up an OTP on your account:
Click on the Options button (your username) on the top right of the trading page, then click Settings.

You will automatically be directed to the Security page. Select Multi-Factor Authentication.

Click the toggle switch to enable OTP. It will move to the right and become blue when enabled.

If you wish to disable OTP at any point, click the toggle switch again until it is left aligned.
Signing in using OTP
Go to the sign-in page.
You will not be asked to complete OTP if you Sign in with Google, even if it's enabled.
Input your email and password and click Sign In.

If you have both OTP and passkeys enabled, you will be prompted to select between the two verification methods. Ensure the OTP option is selected then click Sign In.

You will be prompted to input the code. Check your email for a unique passcode as displayed below.

Navigate back to the sign in screen, input the code and click Sign in.

If successful, you will be directed to Rails' main trading page.
Check out our troubleshooting tips if you are having trouble logging in.
Passkeys
Passkeys are secure digital credentials stored on your device, offering an extra security layer for your account. They use advanced encryption and biometric verification (e.g., Face ID, fingerprint) or a device PIN for quick and secure identity verification. Physical security keys like YubiKey can also be used as passkeys to enhance security.
Setting up a Passkey
Click on the Options button (your username) on the top right of the trading page, then click Settings.

You will automatically be directed to the Security page. Select Multi-Factor Authentication.

Click on Create Passkey.

Your device may suggest a specific passkey method (e.g. 1Password, iCloud, etc.) based on what you have available. Follow the prompts to set up the suggested passkey, or click X or Cancel until you get a screen similar to the below screenshot to select your preferred passkey method.

Follow the verification prompts on your device, or jump to supported passkeys to see steps for specific, common passkeys.
Once completed, you should see your passkey listed in your settings page as shown below.

Ensure the toggle for Passkeys is on. It will be blue and switched to the right.

To add additional passkeys, simply click the Add Passkey button in the bottom left corner and repeat this process.

Edit your passkey names for easier identification by clicking the pencil icon
in the Action column.
Signing in using Passkeys
Go to the sign-in page.
You will not be asked to verify via passkey if you Sign in with Google, even if it's enabled.
Input your email and password and click Sign In.

If you have both OTP and passkeys enabled, you will be prompted to select between the two verification methods. Ensure Sign in with a passkey is selected then click Sign In.

Follow the prompts on your passkey. If successful, you will be directed to Rails' main trading page.
Check out our troubleshooting tips if you are having trouble logging in.
Supported Passkeys
Rails supports a broad list of secure FIDO2-based passkeys for MFA. FIDO2 passkeys are secure digital credentials stored directly on your device. They use cryptographic keys paired with biometric verification (like fingerprint or facial recognition) or a PIN. Because passkeys are device-bound, they’re significantly more resistant to common cyber threats like phishing, credential theft, and password reuse attacks.
Setting up Common Passkeys
If you have multiple passkey options on your device, it will decide the hierarchy of which one you are presented with first. Click X or Cancel when prompted if you wish to use or set up a different passkey.
Step-by-step instructions on how to set up some of the most common passkeys can be found in the expandable sections below:
iCloud Keychain
Mac users that utilize biometric (fingerprint) scan set up access to their passkey by using the following steps:
Your device may prompt you to setup a different passkey (e.g. Chrome, 1Password, etc.) proactively. Click X or Cancel until you get to the following screen, then select iCloud Keychain.

Use your fingerprint to allow for a passkey to be saved on your iCloud Keychain.

If saved successfully, this passkey will be saved in your security settings under passkeys as iCloud Keychain.

Click the pencil icon to edit the passkey name if you're adding multiple passkeys or devices.
1Password
Users who have the 1Password browser extension are able to use their 1Password account to securely store their passkey by following these steps:
Unlock your 1Password account (if prompted).

Click New Item on the 1Password prompt and then click Save.

Your passkey is automatically created in 1Password and if successful, it will be listed in Settings > Security > MFA > Passkeys as 1Password.

Click the pencil icon to edit the passkey name if you're adding multiple passkeys or devices.
Chrome Profile
Users who have biometrics set up in their Chrome browser can also use this as a passkey method.
Your device may prompt you to setup a different passkey (e.g. iCloud, 1Password, etc.) proactively. Click X or Cancel until you get to the following screen, then select Your Chrome profile.

Ensure the right profile is selected and click Continue.

Provide biometric scan or password to continue.

If saved successfully, this passkey will be saved in Settings > Security > MFA > Passkeys. as Chrome on Mac.

Click the pencil icon to edit the passkey name if you're adding multiple passkeys or devices.
Device QR Code or Security Key
Users are able to access their passkey by using another device or private security key by using the following steps:
Your device may prompt you to setup a different passkey (e.g. iCloud, 1Password, etc.) proactively. Click X or Cancel until you get to the following screen, then select Use phone, tablet or Security Key

When presented with this screen, you can choose to either use a camera on another device to scan the QR Code or insert and touch your security key to set up the passkey.

Follow the prompts on your device.
If saved successfully, this passkey will be visible in your passkey list in Settings > Security > MFA > Passkeys.
Last updated
Was this helpful?

