Account Security
LiveThe security steps that protect your membership, rewards, and cashout settings.
HeartBadge separates basic account access from approval of sensitive actions. A six-digit email code can verify your address and open your dashboard. Passkeys and authenticator codes provide stronger confirmation before rewards move or important account settings change.
Security methods
| Method | What it does | Important note |
|---|---|---|
| Email code | Verifies your membership email and supports sign-in | Codes expire and should never be shared |
| Passkey | Approves supported actions with a trusted device or security key | Keep access to at least one registered device |
| Authenticator 2FA | Generates changing six-digit codes for sensitive actions | Save the backup codes when setup is completed |
What each step unlocks
The dashboard shows the requirements for the action you are trying to take. In general, sending rewards requires a verified email and at least one stronger security method: a passkey or authenticator 2FA. Some destination or cashout changes can require authenticator 2FA specifically.
- Verify your email. Enter the six-digit code delivered to the membership address.
- Add a passkey. Register a device, platform account, or hardware security key you control.
- Set up authenticator 2FA. Scan the setup code with a compatible authenticator and save the backup codes.
- Add a cashout option. Complete any additional security check shown before adding or changing a destination.
Recommended setup
Use both a passkey and authenticator 2FA when possible. They protect the account in different ways and give you more options if a device is lost. Keep backup codes somewhere private and separate from the device running your authenticator app.
Protect your codes and approvals
- HeartBadge support will not ask for an email or authenticator code.
- Do not approve a passkey prompt you did not initiate.
- Do not scan an unexpected 2FA setup QR code.
- Review the destination and amount before approving a transfer.
- Contact support when the dashboard shows a security change you do not recognize.
Recovery
Start with a registered passkey, your authenticator app, or an unused backup code. If none are available, contact support@heartbadge.com. Recovery may require additional verification and is not guaranteed to be immediate.
See Email Verification, Passkeys, and Two-Factor Auth for setup instructions.