1. Two-step authentication (2FA)
On top of your password, the account can ask for a temporary six-digit code generated by an authenticator app on your phone. We accept the commonly used apps that follow the TOTP standard. Text messages are not our main method, because they are easier to intercept.
The second step is mandatory to request a withdrawal and to change the email, the phone number or the permissions of an API key. For signing in it is optional, but we strongly recommend it. When you switch it on you receive backup codes: keep them away from your phone, because they are the recovery route if you lose it.