Security tips
Your account holds a balance and an order history. These are the things that keep both yours.
Turn on two-factor authentication
A password alone can be guessed, reused or phished. With a second factor on, knowing your password is not enough to sign in as you.
Set it up from your account page. You will be given recovery codes at the same time — store them somewhere that is not your password manager, because that is the one place you cannot reach if you lose access to it.
Check where you are signed in
Your account page lists every device with an active session, and when each was last used. If you do not recognise one, sign it out and change your password.
- Sign out of shared or public computers rather than closing the tab
- Change your password if you have used it anywhere else
- Nobody here will ever ask you for it
Treat API keys like passwords
An API key can place orders and spend your balance. It is shown once, when you create it, and never again — if you lose it, delete it and make another rather than hunting for a copy.
- Give each integration its own key, so one can be revoked without breaking the rest
- Keep keys out of source control, screenshots and support messages
- Delete keys you have stopped using
Watch what your money is doing
- Your wallet holds the cost of an open order rather than spending it, so a balance that looks low may simply be reserved
- Every credit and debit appears in the wallet ledger with what caused it
- If something does not add up, open a ticket — it arrives with your order history attached
Beware of anyone offering a better price elsewhere
Payments happen here, on this site, and only into the wallet. An offer to settle privately — by direct transfer, a different site, or a "staff member" messaging you first — is not one of ours.