DocumentationAccount Security

Account Security

Protect your Inkress merchant account with modern authentication methods including passkeys and two-factor authentication.

Why Account Security Matters

As a merchant handling financial transactions, your Inkress account is a valuable target for attackers. Protecting your account with strong authentication methods helps prevent:

  • Unauthorized access to your payment dashboard and customer data
  • Fraudulent changes to your payout settings or bank accounts
  • Unauthorized refunds or transaction manipulation
  • Reputational damage from compromised accounts

Available Security Features

Inkress offers multiple layers of security to protect your account. We recommend enabling at least one additional authentication method beyond your password.

Passkeys

The most secure and convenient way to sign in. Use your device's biometrics (Face ID, Touch ID, Windows Hello) or password manager to authenticate.

Phishing-resistantNo passwords to stealRecommended
Learn about Passkeys

Two-Factor Authentication

Add an extra layer of security with time-based one-time passwords (TOTP). Works with popular authenticator apps like Google Authenticator or Authy.

Works offlineIndustry standard
Set up 2FA

Which Should I Choose?

FeaturePasskeys2FA (TOTP)
Phishing resistantPartial
No codes to enter
Works without smartphone
Syncs across devices
Works offline
Ease of setupVery EasyModerate

Security Best Practices

Use a unique, strong password

Even with 2FA enabled, use a password you don't use anywhere else. Consider using a password manager to generate and store complex passwords.

Register multiple passkeys

Add passkeys from multiple devices (phone, laptop, security key) so you can still access your account if one device is lost or broken.

Save your 2FA recovery codes

When setting up 2FA, you'll receive recovery codes. Store these in a secure location (not on the same device as your authenticator app).

Review your active sessions

Periodically check your account for unfamiliar sessions or devices and revoke access to any you don't recognize.