Security Settings
Security Settings
Security settings help protect your admin panel and customer accounts from unauthorized access.
Two-Factor Authentication (2FA)
Enable 2FA under Settings → Security → Two-Factor Authentication:
- Optional — Users may enable 2FA from their account settings
- Required for Admins — All admin roles must set up 2FA before accessing the panel
- Required for All — All users (customers and admins) must use 2FA
Supported methods: authenticator app (TOTP — Google Authenticator, Authy) and backup recovery codes.
Session Configuration
- Session lifetime — How long before idle sessions expire (default: 120 minutes)
- Remember Me duration — How long "remember me" sessions last (default: 30 days)
- IP binding — Invalidate sessions if the IP address changes (prevent session hijacking)
Login Attempt Throttling
The platform automatically blocks accounts for 15 minutes after 5 failed login attempts. Configure the threshold and lockout duration under Settings → Security → Login Throttling.
Last updated: 5/20/2026