Platform & Security
2FA (two-factor authentication) requires a second proof of identity in addition to a password, typically a time-based code from an authenticator app or a code sent by email, so that a stolen password alone is not enough to log in or to perform a sensitive action.
Passwords are reused, phished and leaked; a trading dashboard that can add API keys, change targets or delete accounts with a password alone is only as safe as the weakest place that password was ever used. 2FA turns a leaked password into a nuisance instead of a takeover. It matters on the platform, on the exchange and on TradingView, which will not even show the webhook field until 2FA is enabled on the TradingView account.
AlgoVesta supports authenticator-app and email-based second factors on the dashboard, and applies a step-up check to actions that cannot be undone: deleting the account, deleting an MT5 account or an exchange key, and enabling live trading on an account. For those actions the platform requires fresh proof of identity, a recent sign-in with the provider you used (Google, Apple or password) or a valid second-factor code, rather than relying on an existing session token. Access tokens themselves are short-lived and refreshed silently, so a captured token expires quickly. Live MCP keys and the actions that reduce safety require the step-up; actions that increase safety, such as disabling live trading, do not, so protecting yourself is never made harder. New sign-ins from an unfamiliar device or location trigger an email notice. See the Security page.
A user's password is phished. The attacker logs into the dashboard but cannot delete the user's exchange key or enable live trading on the paper account without the second factor, and the user receives a new-device sign-in email, changes the password and reviews sessions. The exchange key itself was trade-only and IP-restricted, so even a successful dashboard login would not have allowed a withdrawal.