Signing in and two-factor login
Screen: Sign in, address /login.
Your login is the phone number you registered with — not your e-mail. The account is tied to one site: if you have an account on a neighbouring service, it will not open here, even with the same phone number.
Signing in
| № | Action |
|---|---|
| 1 | Enter the phone number in international format |
| 2 | Enter the password |
| 3 | Press Sign in |

No account yet? Registration is on the same screen, on the Sign up tab.
If the phone number is unknown or the password is wrong, the cabinet shows the same message in both cases. This is deliberate: otherwise the form would tell a stranger which numbers are registered.
When the cabinet asks for something besides the password
There are two different reasons, and they look almost the same on screen.
You have not signed in for a long time. If your last activity is more than a year old, the cabinet sends a code by SMS and asks for it once. This is not two-factor authentication — it is a one-off confirmation that the number is still yours.
You turned on two-factor authentication yourself. Then the cabinet asks for it every time, and the code comes from the method you set up, not by SMS.
Separately: after several wrong passwords in a row the account is locked, and the cabinet switches to asking for a code from SMS instead of the password. The number of attempts is set by the operator, so it differs between services. There is also a limit on the sign-in form itself — a few attempts per minute from one address; after that the form asks you to wait, and waiting is the only thing that helps.
Two-factor authentication
Set up on the Settings → Password and security screen, address
/settings?tab=password-and-security. Three methods, and they can be combined.
| Method | What it is | Where the code comes from |
|---|---|---|
| Authentication program | An app on your phone (any TOTP app) | The app, a new code every 30 seconds |
| Security key | A hardware key or the built-in one on your device | The key itself, no code to type |
| Backup codes | Eight one-time six-digit codes | The list you saved when you turned them on |
Backup codes exist for the case when the first two methods are unavailable — the phone is lost, the key is at home. Each code works once and disappears after use. Eight are issued; when they run out, generate a new set.
When you switch Authentication program on, the cabinet creates the secret immediately, before you type anything — the QR code you see is already tied to your account. If you close the window without entering the code from the app, two-factor authentication stays switched on, and at the next sign-in the cabinet will ask for a code that no app is generating yet.
If that has already happened, sign in with a backup code and set the method up again from the beginning. If there are no backup codes either, only support can help.
Switching on any of the three methods ends all your other sessions. This is intended: if someone else was signed in to your account, they are signed out at that moment. You stay in the current tab.
Choosing a different method at sign-in
If two-factor authentication is on and the usual method is out of reach, the sign-in screen lets you switch to another one — for example, from the app to a backup code. Only methods you have already set up are offered.
If you have lost the password
On the sign-in screen, press Restore password.
| № | Action |
|---|---|
| 1 | Enter the phone number of the account |
| 2 | Enter the code that arrives by SMS |
| 3 | Wait for the second SMS — it contains a new password |

You cannot choose your own password at this step: the service generates it and sends it by SMS. Sign in with it and change it in the settings.
If the number is not registered on this site, the screen still says the request went through, and no SMS arrives. The form deliberately does not tell whether the number exists.
Changing the password
Settings → Password and security. The current password is not asked for — you are already signed in. The minimum length is six characters; alongside the field the cabinet shows recommendations for a strong password, and they are recommendations, not restrictions: a six-character password will be accepted.
Where to see who signed in
Settings → Access log, address /settings?tab=visits. Web sign-ins, API calls and SMPP
connections, with time and address. The log is read-only: you cannot end someone else's
session from it, and there is no "sign out everywhere" button. If you see a stranger there —
change the password and switch on two-factor authentication; changing the methods ends the
other sessions.
How long the session lasts
The sign-in is valid for 30 days, after which the cabinet asks for the password again.