Account security (2FA)
FlashProxy supports two-factor authentication (2FA) with an authenticator app. With 2FA enabled, signing in takes your password plus a 6-digit code from your phone — so a stolen password alone can't access your account, your balance, or your proxies.
2FA is optional and free. It applies to password sign-in: if you log in with Google or GitHub, your provider's own two-step verification protects your sign-in instead, and the 2FA option is not shown.
Enabling 2FA
- Go to Settings → Security in the dashboard.
- In the Two-factor authentication card, click Enable 2FA and confirm your password.
- Scan the QR code with any authenticator app — Google Authenticator, Authy, 1Password, Microsoft Authenticator all work. On a laptop, you can instead copy the manual setup key and paste it into your app.
- Enter the 6-digit code your app shows to confirm.
You'll then see your backup codes — save them before leaving the page (see below).
Backup codes
When you enable 2FA you receive 10 one-time backup codes. Each code can be used once in place of an authenticator code if you lose access to your phone.
- They are shown only once. Copy or download them at that moment and store them somewhere safe (a password manager is ideal). They cannot be viewed again later.
- The Security card shows how many you have left, and Regenerate issues a fresh set of 10 at any time. Regenerating invalidates all previous codes.
- If you run low (or hit zero), regenerate — the card will warn you.
Signing in with 2FA
After entering your password you'll be asked for the 6-digit code from your authenticator app.
Lost your phone? Choose the backup-code option on the sign-in screen and enter one of your saved backup codes. Each code works once — after you're in, consider regenerating a fresh set in Settings. A security notification email is sent whenever a backup code is used.
Disabling 2FA
In Settings → Security, click Disable, then confirm your password and a current authenticator code. Your enrolled authenticator and any remaining backup codes are removed immediately. You can re-enable at any time — re-enrolling generates a new QR code and secret, so delete the old FlashProxy entry from your authenticator app first.