Skip to content

Merchant dashboard

Sandbox

Security

Phase 1 preview — all figures below come from placeholder data.

TOTP authenticator

Enabled

mandatory for every user

Passkeys

2

required for owner and admin roles

Recovery codes left

8

single-use, stored offline

Two-factor authentication is enforced

Sign-in without a second factor is rejected at the edge. Payout and settlement-wallet changes additionally re-prompt for 2FA, and a new destination stays under a 24 h time-lock before the signer will act on it.

Active sessions

Revoking a session invalidates its refresh token immediately; API keys are unaffected.

3 active sessions
DeviceIP addressLocationLast seenStatus
Chrome 140 · macOS203.0.113.10Berlin, DEthis device
Safari 18 · iOS203.0.113.44Berlin, DEsigned in
Firefox 133 · Linux198.51.100.7Amsterdam, NLsigned in

Audit trail

Append-only and hash-chained — each row commits to its predecessor, so a deletion or an edit is detectable.

4 recorded security events
ActionActorIP addressWhen
Settlement wallet added (bitcoin) — 24 h time-lock started[email protected]203.0.113.10
API key created — sk_live_1Zc5 (read, payout)[email protected]203.0.113.10
Webhook signing secret rotated — wh_01J9ZV4D…[email protected]198.51.100.7
Role changed — [email protected] → finance_viewer[email protected]203.0.113.11