# Security (/merchants/security)

Two-factor sign-in is required for every Fianto account and cannot be turned off. This page covers
what you can change afterwards, all on **Account and security**: the device that makes your codes,
your recovery codes and, once your account is approved, your receiving wallet.

## Before you start [#before-you-start]

* You can sign in, and you know your password.
* You have a code from your current authenticator app, or an unused recovery code.
* To change your receiving wallet: your account is approved, and the new wallet is in this browser.

## Steps [#steps]

**Step 1.**

### Open Account and security [#open-account-and-security]

Choose **Account and security** in the account menu (your avatar) or in the sidebar. The
**Two-factor sign-in** panel reads "On. Signing in needs a code from your authenticator app."

**Step 2.**

### Move two-factor sign-in to a new phone [#move-two-factor-sign-in-to-a-new-phone]

Open **Move two-factor sign-in to a new device**. Enter your password and a code from your current
app (or a recovery code), then click **Continue**. Scan the new QR code with the new phone, enter the
code it shows and click **Use this new device**.

Your old device and your old recovery codes stop working. Fianto shows 10 new recovery codes, once:
save them, then click **I have saved my recovery codes**. Every other session of your account is
signed out.

**Step 3.**

### Replace your recovery codes [#replace-your-recovery-codes]

Each recovery code works once. To get a fresh set, go to **Recovery codes**, enter your **Current
password** and an **Authentication code or recovery code**, and click **Generate new recovery
codes**. Your existing codes stop working immediately. Save the new ones: they are shown once.

**Step 4.**

### Change your receiving wallet [#change-your-receiving-wallet]

Once your account is approved, the **Receiving wallet** panel appears. Open **Change wallet**, enter
your **Current password** and an **Authentication code or recovery code**, then choose the new wallet
and sign the message it shows. Signing a message costs nothing and moves nothing.

The panel then shows "Waiting for Fianto to review this change:" with the new address, and Fianto
tries to email you "A wallet change was requested on your Fianto account". An admin approves or rejects the
request. Until it is approved, payments keep going to your current wallet.

**Step 5.**

### Withdraw a wallet change, if you need to [#withdraw-a-wallet-change-if-you-need-to]

While a change is waiting, you can click **Withdraw this request**. Nothing changes, and Fianto tries
to email you "Your wallet change request was withdrawn". You can have only one change waiting at a time, so
withdraw it before asking for a different wallet.

> **Existing subscriptions keep paying your old wallet:**
>
> After a wallet change is approved, one-time payments and new subscriptions pay the new wallet.
> Subscriptions that already exist keep paying the old wallet: they are set up on chain to pay it, and
> that cannot be moved. Keep the old wallet safe until they have all ended. No admin can edit your
> wallet directly; a change always goes through this request.

> **The new wallet needs a USDC token account:**
>
> Like your first wallet, the new one must already have a USDC token account, or creating a checkout
> fails. Send it any amount of USDC once.

## Check it worked [#check-it-worked]

> After moving to a new phone, sign in: the **Two-factor code** screen accepts a code from the new
> phone. After a wallet change is approved, the **Receiving wallet** panel reads "Payments go to" the
> new address, and Fianto tries to email you "Your new receiving wallet is approved". If the change is
> rejected, the panel shows "Last change request" as "Not approved", and payments keep going to your
> current wallet.

## Troubleshooting [#troubleshooting]

| You see | Why | Fix |
|---|---|---|
| "Too many incorrect codes. Try again later." | 10 wrong codes in a row locked your second factor, for 15 minutes the first time, then twice as long each time after, up to 24 hours. | Wait for the lock to end. There is no way to unlock it yourself. |
| "Setup timed out after 10 minutes." | The new QR code was not confirmed within 10 minutes. | Start again to get a new QR code. |
| "You already have a wallet change waiting for review." | Only one wallet change can wait at a time. | Withdraw it first, then ask for the other wallet. |
| "That is already your receiving wallet." | You chose the wallet payments already go to. | Choose a different wallet. |
| "That wallet already receives payments for another Fianto account." | One wallet cannot serve two merchants. | Use a different wallet. |
| An email about a wallet change you did not ask for | Someone signed in to your account requested or withdrew a change. | Write to support@fianto.xyz straight away. |

## If you lose your phone and your recovery codes [#if-you-lose-your-phone-and-your-recovery-codes]

A recovery code signs you in without your phone. If you have lost both, only Fianto support can reset
your two-factor sign-in: write to [support@fianto.xyz](mailto:support@fianto.xyz). After the reset you get the email "Two-factor
sign-in was reset on your Fianto account": your recovery codes are deleted and every session is
signed out. Sign in with your password and set up two-factor sign-in again; until you do, the
dashboard only lets you set it up.

## See also [#see-also]

- [Your account](/merchants/your-account): Sessions, log out, password changes and sign-in lockouts.

- [Set up your business](/merchants/set-up-your-business): Your first two-factor setup and wallet proof.

- [Subscriptions](/merchants/subscriptions): How subscriptions renew and how to cancel them.