> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rns.id/llms.txt
> Use this file to discover all available pages before exploring further.

# Secure Your RNS.ID Account with Password and 2FA

> Manage your RNS.ID password and authenticator-based 2FA, follow setup prompts, and protect account verification codes.

Use a strong password and authenticator-based two-factor authentication to protect your RNS.ID account.

## Password requirements

A password created during registration, password reset, or account settings must:

* contain **8–128 characters**;
* include at least one uppercase English letter, one lowercase English letter, one number, and one supported symbol;
* contain only English letters, numbers, and the supported symbols below; and
* match the confirmation field.

Use at least one symbol from this supported set:

```text theme={null}
~ ! @ # $ % ^ & * ( ) _ + ` - = [ ] { } | ; ' : " , . / < > ? \
```

Spaces and characters outside that set are not accepted. When changing or resetting an existing password, the new password must also differ from the current password. Use a unique password and store it in a trusted password manager.

## Change your password

1. Sign in and open **Settings → Account**.
2. Under **Security**, select **Change Password**.
3. Complete the fields shown for your account:
   * If a password is already set, enter the **Current Password**, **New Password**, and **Confirm New Password**.
   * If the account does not yet have a password, enter the **New Password** and **Confirm New Password**. A current password is not requested.
4. Select **Save** and wait for RNS.ID to confirm that the password was changed.

The new password must meet the [password requirements](#password-requirements) and cannot be the same as the existing password.

<Warning>
  The current **Change Password** action does not guarantee that other signed-in browsers or devices are signed out. If you suspect unauthorized account access, do not rely on this routine action alone. Use [Reset your password](/getting-started/reset-your-password), which ends existing signed-in sessions after a successful reset, and [contact RNS.ID Support](/support/contact-us).
</Warning>

If you cannot sign in, use [Reset your password](/getting-started/reset-your-password). Password reset is available through the verified account email; wallet recovery phrases are never part of that flow.

## Enable two-factor authentication

1. Open the 2FA control in account settings.
2. Scan the displayed QR code with an authenticator app such as Google Authenticator or Authy.
3. Select **Next** to continue to the verification step.
4. Request the email verification code.
5. Enter the six-digit email code and the current six-digit authenticator code.
6. Confirm that RNS.ID reports 2FA as enabled.

The authenticator app is time-based. If a valid-looking code fails, set the device date and time to update automatically and try the newest code.

Treat the setup QR code as an account-security secret. Scan it only in the intended authenticator app; do not save, copy, or share it. Follow the current setup screen rather than relying on a fixed expiration time from an older guide.

## If 2FA sign-in is locked

Five consecutive failed authenticator codes during sign-in lock 2FA verification for 15 minutes. RNS.ID sends a security-alert email when the lock begins.

During the lock:

1. Stop entering codes and wait for the full 15 minutes.
2. Set the authenticator device's date and time to automatic.
3. Confirm that you selected the correct RNS.ID entry in the authenticator app.
4. After the lock ends, enter only the newest code.

If you did not cause the failed attempts, use [Reset your password](/getting-started/reset-your-password) to end existing signed-in sessions and [contact RNS.ID Support](/support/contact-us). Do not rely only on **Change Password**, and do not approve an unexpected sign-in, verification request, wallet signature, or transaction.

## Disable two-factor authentication

Open the 2FA control, select the disable action, and enter the codes requested by the form. Confirm that the setting changes only after RNS.ID reports success.

<Warning>
  Do not share an authenticator QR code, email verification code, or six-digit authenticator code. RNS.ID Support will never ask for those secrets.
</Warning>

## Protect wallet access too

Account 2FA does not protect the seed phrase or private key of a connected self-custody wallet. Keep wallet recovery material offline and inspect every signature or transaction. See [Security and scam reporting](/support/security-and-scam-reporting).
