Client area & billingAccount & security
Secure your client account with two-factor authentication
Turn on two-factor authentication for your HyperDC client account, keep the backup code safe, use a strong password and know what to do if you lose your phone.
- Beginner
- 6 min read
- Updated
Tested on: HyperDC client area
On this page
Your HyperDC client account controls your servers, domains, invoices and saved payment methods. If someone learns your password, two-factor authentication (2FA) still stops them: signing in then needs a code from a device only you hold. This guide turns it on and covers the other settings on the Security Settings page.
Before you start
- A smartphone with an authenticator app, or a password manager that can generate time-based codes (TOTP).
- Your current client area password.
- A safe place for the backup code, such as your password manager.
Step 1: Open Security Settings
Sign in, open the account menu (your name at the top right) and choose Security Settings. The page shows whether Two-Factor Authentication is enabled or disabled, your password, your most recent sign-in and its IP address.
Step 2: Enable two-factor authentication
- Under Two-Factor Authentication, select Enable Two-Factor Authentication.
- Choose Time Based Tokens ("Get codes from an app like Google Authenticator or Duo") if more than one method is offered, and select Get Started.
- Scan the QR code with your authenticator app. If you cannot scan it, type the secret key shown next to it into the app.
- Enter the six-digit code that the app shows and confirm.
- The page shows Your Backup Code is followed by the code. Save it now: "Treat the backup code the same as you would your password."
Verify: the page says "Two-Factor Authentication is now enabled". Sign out and sign in again: after your password, you are asked for a code from the app.
Step 3: Use a strong, unique password
On Security Settings, choose Change Password. Use a long password that you use nowhere else; a password manager can generate and remember it. Reused passwords are the most common way accounts are taken over, because leaks from other websites are tried everywhere.
Step 4: Review the other settings
- Change Security Question: some requests, for example by phone or ticket, may use it to confirm your identity. Choose an answer that cannot be found online.
- Linked Accounts: sign-in services connected to your account. Remove the ones you no longer use.
- Most recent sign-in: if the time or IP address does not look like you, change your password at once and open a ticket.
Signing in with two-factor authentication
After your email and password, enter the current code from your app. Codes change every 30 seconds, so make sure the clock on your phone is set automatically.
If you cannot use the app, select Can't Access Your 2nd Factor Device? and then Login using Backup Code. After the backup code is used it is reset, and a new one is shown: save the new code.
Good habits
- One login per person. Invite colleagues under User Management instead of sharing your login; see users and contacts.
- Check before you click. Sign in by typing the address of our website yourself or from a bookmark, not from links in unexpected emails. Never enter your password or codes on a page you reached from a message you did not expect.
- Keep your email account safe too. Password resets go to your email address, so protect that account with 2FA as well.
Troubleshooting
The code is always rejected. The clock on your phone is probably wrong. Turn on automatic date and time, then try again.
I replaced my phone. If your authenticator app syncs or backs up your codes, restore them on the new phone. Otherwise sign in with the backup code, then disable and enable two-factor authentication again to scan a new QR code.
I lost both my phone and the backup code. Contact us; we will verify that the account is yours before we turn two-factor authentication off.
Next steps
- Give colleagues their own access: users and contacts.
- Protect your servers too: secure a new Linux server and secure a Windows server.
Frequently asked questions
Which authenticator app should I use?
Any app that supports time-based one-time passwords (TOTP), such as the authenticator built into your password manager, Google Authenticator, Microsoft Authenticator or similar apps. The codes work offline.
What is the backup code for?
It lets you sign in if you cannot use your authenticator, for example after losing your phone. Each backup code works once; after you use it, a new one is shown. Store it in your password manager or another safe place.
I lost my phone and my backup code. How do I get back in?
Open a support ticket from another account user if you have one, or contact us through the contact form. We will verify that you own the account before we turn off two-factor authentication, which takes some time by design.
Does two-factor authentication also protect my servers?
No. It protects your client account. Servers have their own logins: protect them with SSH keys, strong passwords and a firewall.
Should every user of my account turn it on?
Yes. Each user signs in with their own login, and each login should have its own second factor. As the account owner, ask every user you invite to enable it.