> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mirrorpip.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Mirrorpip Account Security: 2FA, Passwords, and API Keys 

> Enable two-factor authentication, change your password, and follow best practices to protect your exchange API key and Mirrorpip account.

Protecting your Mirrorpip account is important — your account has access to trade on your connected exchange. Use the security settings below to add layers of protection and stay safe.

## Changing your password

<Steps>
  <Step title="Open Security settings">
    Go to **Settings → Security** in the Mirrorpip app.
  </Step>

  <Step title="Tap Change Password">
    Tap the **Change Password** option.
  </Step>

  <Step title="Enter your current and new password">
    Type your current password, then enter your new password twice to confirm. Your new password must be at least 8 characters and include a mix of letters and numbers.
  </Step>

  <Step title="Save">
    Tap **Update Password**. You'll be asked to log in again with your new password.
  </Step>
</Steps>

## Two-factor authentication (2FA) (coming soon)\*

Two-factor authentication adds a second verification step when you log in, protecting your account even if your password is compromised.

<Steps>
  <Step title="Go to Settings → Security → Two-Factor Authentication">
    Tap **Enable 2FA** to begin setup.
  </Step>

  <Step title="Choose your 2FA method">
    Mirrorpip supports authenticator app-based 2FA (such as Google Authenticator or Authy). Select **Authenticator App**.
  </Step>

  <Step title="Scan the QR code">
    Open your authenticator app and scan the QR code displayed by Mirrorpip. This links your account to the app.
  </Step>

  <Step title="Enter the verification code">
    Enter the 6-digit code your authenticator app generates to confirm the setup.
  </Step>

  <Step title="Save your backup codes">
    Mirrorpip provides backup codes you can use if you lose access to your authenticator app. Store these in a safe place — they are shown only once.
  </Step>
</Steps>

<Warning>
  If you lose access to your 2FA device and your backup codes, you may be locked out of your account. Keep your backup codes somewhere secure and separate from your phone.
</Warning>

## Managing your exchange API key

Your connected exchange API key is used to place and close trades in your exchange account. Keep it secure:

* **Never share your API key or secret** with anyone, including Mirrorpip support staff.
* **Only grant trading permissions** — never enable withdrawal permissions.
* **Rotate your key periodically** — delete the old key on your exchange and reconnect in Mirrorpip via **Settings → Exchange**.
* **Revoke access immediately** if you suspect your API key has been compromised — go to your exchange's API settings and delete the key, then reconnect with a new one.

## Logging out of all devices

If you believe your account may be compromised, log out of all active sessions:

1. Go to **Settings → Security → Active Sessions**.
2. Tap **Log Out All Devices**.
3. You'll be signed out everywhere and must log in again.

<Note>
  Logging out of all devices does not stop active mirroring. Mirrorpip continues to mirror trades using the stored API key until you explicitly stop mirroring or disconnect your exchange.
</Note>

## Reporting a security issue

If you find a security vulnerability or suspect unauthorized access to your account, contact the Mirrorpip security team immediately at [support@mirrorpip.com](mailto:support@mirrorpip.com). or call us at +91- 90400-00409
