Account security
Last updated:
For all PrestaKick users, especially owners.
Previous: Billing and plans · Next: Notifications
Open Account security in the account menu to manage two-factor authentication, backup codes, and login sessions.
Email and password
Once registered, verify your email within 24 hours. If you see Account is not verified, open PrestaKick's email or ask to resend the link if the old link has expired.
Use a unique password for PrestaKick. Don't reuse your email password or PrestaShop admin account.
If you forget your password, select Forgot password and follow the link sent via email.
Enable two-factor authentication
PrestaKick uses TOTP codes from an authenticator app.
- Open Account security.
- Start setting up two-factor authentication.
- Scan the QR code with an authenticator app.
- Enter the six-digit code that is displayed to confirm.
- Save the recovery codes supplied.
Once enabled, you need to enter the TOTP code when you log in or when the system asks for re-authentication.
If a code is rejected, wait for a new one and check that your phone sets its date and time automatically.
Recovery codes
Recovery codes are backup codes that are used when you can't access the authenticator app. Each code can only be used once.
- Save in a password manager or a safe place off your phone.
- Don't send via unprotected group chats or emails.
- Create a new set of codes if you suspect that it has been exposed or has been used up.
When you create a new set, the old codes stop working. If you lose both your authenticator device and recovery codes, contact support through an official channel. Account recovery depends on successful verification.
Login sessions
The Sessions section shows signed-in devices and sessions. You can revoke one session or all sessions.
Revoke a session when:
- You signed in on a shared device.
- You lost a device.
- You do not recognize a session.
- You suspect unauthorized access to the account.
Revoking a session signs out the corresponding device.
Re-authentication for sensitive operations
PrestaKick requires re-authentication before some actions, such as:
- Access or change AI settings.
- Transfer of ownership.
- Delete customer data in accordance with GDPR.
- Rotate the security key.
- Change or cancel the plan.
- Actions in the Danger zone.
Follow the on-screen prompts and don't share the authentication code with others.
Respond to an unfamiliar sign-in alert
- Change your password.
- Revoke sessions that are not recognized, or revoke all sessions.
- Regenerate the recovery codes if necessary.
- Check the shop's member list.
- Check for billing changes and rotated connection keys.
- Contact support if you still see abnormal activity.
Support doesn't need your password or TOTP code to process the request.
Initial security checklist
- Email verified.
- Using a unique password for PrestaKick.
- Two-factor authentication enabled.
- Saved recovery codes off the phone.
- Each member uses their own account.
- Owner knows how to revoke a login session.