Docs — Risk & safety
Setting up two-factor authentication
How to enrol 2FA on AlgoThink with Google Authenticator, why live trading requires it, and what happens if you disable it.
Two-factor authentication is available on every AlgoThink account and is required before live trading unlocks. It uses standard TOTP codes, so any authenticator app works — Google Authenticator, Authy, 1Password, Bitwarden and others.
Enrolling
- Open Account in the sidebar and go to the Security tab.
- Press Set up 2FA.
- Scan the QR code with your authenticator app, or enter the setup key manually if you'd rather type it.
- Enter the six-digit code the app shows and press Confirm and enable 2FA.
From then on, logging in asks for a code after your password.
What 2FA does and doesn't cover
- Login asks for a code every time.
- Trades don't. Once you're logged in, approving a suggestion never prompts for a code — that would make timely trading impossible.
- Live trading requires it. You can't switch to live mode without 2FA enrolled, and disabling 2FA disarms live trading automatically.
Disabling it
On the same Security tab, enter a current code and press Disable 2FA. Remember this also disarms live orders — that pairing is deliberate, not a side effect.
What to consider
- Save your setup key somewhere safe when you enrol, or keep your authenticator app backed up. Losing your only device means losing account access.
- 2FA protects the account, not the exchange. Your exchange API keys have their own protection — the important one is that they're created without withdrawal permission, so even a worst-case account compromise can't move your funds.
- Enrol before you need it. Doing it while trying to arm live trading in a hurry is the wrong moment.