> ## Documentation Index
> Fetch the complete documentation index at: https://support.wepayments.com.br/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and Login

This guide covers security features available in the WEpayments Dashboard, including two-factor authentication (2FA) with Google Authenticator, password changes, and security requirements for sending payments and creating charges.

## Two-factor authentication (2FA)

Two-factor authentication adds an extra layer of security to your WEpayments account, preventing unauthorized access.

### Why you need 2FA

| **Requirement**                    | **Details**                                                         |
| :--------------------------------- | :------------------------------------------------------------------ |
| **Dashboard login**                | Required after password – 6-digit code from Google Authenticator    |
| **Send payments / create charges** | 2FA must be enabled to perform these actions                        |
| **Without 2FA**                    | You can only view information (even with Moderator or Write access) |

> ⚠️ **Important:** Without two-factor authentication enabled, you will only be able to view information on our dashboard, even if you have editing or moderator access.

## How to enable two-factor authentication

### Step-by-step

| **Step**                             | **Action**                                                |
| :----------------------------------- | :-------------------------------------------------------- |
| **1. Download Google Authenticator** | From your smartphone's app store (Android or iOS)         |
| **2. Access Dashboard**              | Go to Settings > Security and Login                       |
| **3. Find 2FA section**              | Click "Set up new device" under Two-factor authentication |
| **4. Follow instructions**           | Scan the QR code with Google Authenticator                |
| **5. Enter code**                    | Input the 6-digit code generated on your smartphone       |
| **6. Click register**                | Two-factor authentication is now enabled                  |

> 💡 Keep the app installed on your phone – you will need the 6-digit code for every login.

## How 2FA codes work

| **Aspect**         | **Details**                                                     |
| :----------------- | :-------------------------------------------------------------- |
| **Code format**    | 6 digits                                                        |
| **Code frequency** | Changes periodically (every few months)                         |
| **Required for**   | Login, API key creation, API key deletion, IP whitelist changes |

## What happens if you lose access to Google Authenticator

| **Situation**           | **Action required**                   |
| :---------------------- | :------------------------------------ |
| **Lost phone**          | Request a reset from our support team |
| **App uninstalled**     | Request a reset from our support team |
| **Cannot access codes** | Contact support to reset 2FA          |

> ⚠️ **Important:** If you lose access to Google Authenticator, you will need to request a reset. Our support team will guide you through the procedure.

### Available 2FA methods

| **Method**               | **Available?** |
| :----------------------- | :------------- |
| **Google Authenticator** | ✅ Yes          |
| **SMS**                  | ❌ No           |
| **WhatsApp**             | ❌ No           |

> 💡 Currently, only Google Authenticator is available for two-factor authentication.

## Changing your password

| **Step**                      | **Action**                        |
| :---------------------------- | :-------------------------------- |
| **1. Access**                 | Settings > Security and Login     |
| **2. Find password section**  | Locate the change password option |
| **3. Enter current password** | For verification                  |
| **4. Enter new password**     | Choose a strong, unique password  |
| **5. Confirm**                | Save changes                      |

## Security best practices

| **Practice**                            | **Why**                                           |
| :-------------------------------------- | :------------------------------------------------ |
| **Enable 2FA**                          | Required for sending payments/creating charges    |
| **Use strong passwords**                | Prevents unauthorized access                      |
| **Keep Google Authenticator installed** | Required for login and security-sensitive actions |
| **Don't share credentials**             | Each user should have their own account           |
| **Log out when not using**              | Especially on shared computers                    |
