Criptala
Account & security

Security

Protect your account with two-factor authentication, a password, and safe transaction habits.

Your money and crypto are only as safe as your account, so it's worth a few minutes to lock things down. Criptala gives you strong tools for the job — two-factor authentication and an optional password — plus a few habits that keep you clear of fraud. Every control on this page lives on the Account page, where you can "Manage your account and general settings."

Where to find these settings

Open the Account page from the top-right user menu. The Information card shows your Email and Two factor authentication status (a green check next to each once it's verified/enabled), and just below you'll find the Two factor authentication and Password update cards described on this page, right alongside your general account settings.

Some actions ask you to confirm your password first

Enabling, confirming, viewing or regenerating recovery codes, and disabling 2FA all reuse the same "Confirm your password" dialog — "Enter your password to continue." You only need to type it again if you haven't confirmed your password recently; once you have, you can do these actions for a while without being asked again.

Two-factor authentication (2FA)

Two-factor authentication adds a second check when you sign in: after your usual login, we ask for a one-time code that only your phone can generate. Criptala's 2FA uses an authenticator app (TOTP) together with recovery codes — there's no SMS option.

On the Account page, look for the Two factor authentication card: "When two-factor authentication is enabled, we'll ask you for a secure random code during authentication. You can get this code from your preferred authenticator app." Select Configure to open the management dialog, which repeats the same title and description and shows a status badge:

BadgeWhen you see it
Finish enabling two-factor authenticationYou started enrolling but haven't confirmed the code yet.
Enabled2FA is confirmed and protecting your account.
Disabled2FA isn't set up.

Enable 2FA

On the Two factor authentication card, select Configure, then select Enable. Criptala generates a new secret and a set of recovery codes for you.

Scan the QR code using your phone's authenticator application, or enter the setup key shown below it manually if you can't scan. The dialog reads: "To finish enabling two factor authentication, scan the following QR code using your phone's authenticator application or enter the setup key and provide the generated OTP code."

Enter the 6-digit Code your authenticator app generates (required). As soon as the sixth digit is entered, the code is submitted automatically. You can also select Confirm manually.

Confirming asks you to confirm your password first if it's been a while since you last did. Once confirmed, your status changes to Enabled, and you'll see the Two factor confirmed toast — "You will now be required to enter a two factor code when logging in."

Your recovery codes appear during setup — save them now

Right after you enable 2FA, your recovery codes appear in the same dialog. Please save them before you close it (see below) — if you close the dialog without noting them down, you'll need to select Show recovery codes afterwards to see them again.

Recovery codes

If you ever lose your phone, recovery codes are your way back in — so they're worth keeping safe: "Store these recovery codes in a secure password manager. They can be used to recover access to your account if your two factor authentication device is lost."

  • Select Show recovery codes (behind the password-confirmation dialog) to view your current codes if they aren't already showing.
  • Select Regenerate recovery codes to create a fresh set — the new codes replace the old ones, which stop working immediately.

Codes only stay on screen for this session

Recovery codes don't stay visible from one visit to the next — once you close the 2FA dialog, just select Show recovery codes again the next time you want to see them.

Keep your recovery codes safe

Keep your recovery codes somewhere only you can reach — a password manager is ideal. Anyone who has these codes can get into your account, and losing both your authenticator device and your codes can lock you out for good.

Signing in with 2FA

With 2FA on, after your normal login you'll land on the Two factor verification screen: "Please enter the authentication code provided by your authenticator application." Enter your 6-digit code — it submits automatically once complete — or select Continue.

Lost your device? No problem: select Use a recovery code to open a dialog: "If you lost your authenticator device, you can use a recovery code to access your account." Enter one of your saved Recovery codes (placeholder "Enter your code") and select Continue. Each recovery code works once.

Disabling 2FA

Select Disable (behind the password-confirmation dialog) to turn 2FA off: "You will need to configure two factor authentication again if you want to enable it in the future."

2FA can be mandatory on some accounts

On accounts where Criptala requires 2FA, the Configure dialog opens automatically and won't close until you finish enabling it — your only other option in that dialog is Logout. The Disable button doesn't appear at all for these accounts, so 2FA can't be turned back off once it's required.

Password

Criptala is passwordless by default — you don't need a password to sign in, and new accounts start with a random password you never see. So there's a small difference between setting your first password and updating one you already know.

Setting your first password

Because a brand-new account's password is random and unknown to you, the Account page's password form can't create your very first one — it always asks for your current password. Instead, use Forgot your password? on the credentials sign-in screen to request a reset link by email; resetting doesn't need a current password, so this is how you give your account a password you actually know. The reset link is valid for 60 minutes after you request it, and you can request a new one at most once every 60 seconds.

Once you know your password, you can update it whenever you like from the Password update card on the Account page: "Update your password regularly to keep your account safe from intruders." Select Update to open the "Update your password" dialog — "Enter a new password for your account."

How long a password confirmation lasts

Once you confirm your password for a sensitive action (like enabling or disabling 2FA), Criptala remembers it for 3 hours before asking again — after that, the next sensitive action brings back the "Confirm your password" dialog.

FieldRequired?Notes
Current passwordYesMust match your account's existing password.
PasswordYesAt least 8 characters.
Password confirmationYesMust match Password exactly.

Select Update to save, and you'll see the Password updated successfully confirmation.

What goes wrongError message
Wrong current password"The password is incorrect."
New password left blank"The password field is required."
New password shorter than 8 characters"The password field must be at least 8 characters."
Confirmation doesn't match"The password field confirmation does not match."

Staying safe and avoiding fraud

A few simple habits protect you from the most common scams. Criptala shows several of these warnings again, word for word, right before you confirm an order.

Avoid fraud

Every Purchase order confirmation shows an Attention dialog that ends with "Avoid fraud""Do not accept money from third parties for the purchase of cryptocurrencies." Never accept money from someone else to buy crypto on their behalf — it's a common fraud pattern and puts your account at risk. You confirm you've read this by selecting I agree.

When you pay by bank transfer specifically, the same dialog adds two more reminders above it: "Remember that you" "must be the owner of the account used to make the payment." and "Transfers are interbank and subject to bank hours, so your payment may take a while to appear in your account."

Double-check network and address

Before sending crypto, confirm both the network and the address — a sale's confirmation dialog reminds you: "When sending, please take into account network costs to send the exact amount, as indicated on the order." Sending on the wrong network or to the wrong address can mean the funds are unrecoverable. See Wallets for exactly how address format validation and network matching work.

For an extra layer of safety, Criptala automatically screens every wallet address you save for fraud/blacklist risk. If you type a new address directly at checkout and it's flagged, that step stops right away with "The address is not currently available." — see Wallets for the full detail on this screening, including what happens if an address you already saved turns out to be risky.

Every order confirmation also repeats these standing notices, whether or not fraud is involved:

  • "Criptala is not responsible for the incorrect entry of data when creating the order."
  • Buying: "By continuing, you accept that all the funds used to purchase cryptocurrencies are of your property and of lawuful origin, and the cryptocurrencies will be sent to a cryptocurrency wallet of your property and for personal use." (yes, "lawuful" is how it's spelled in the app today.)
  • "Collections exceeding U$S 1.000 and made outside of business hours from 09:00 to 18:15 (UTC-3) will be processed the following business day."

Criptala will never ask for your codes

We will never ask for your recovery codes or your authenticator codes outside the app's own sign-in screen. If anyone requests them by email, phone, or message, it's a scam — don't share them.

API tokens (Business profiles only)

If your active profile is Business, the same account menu also gives you API tokens for programmatic access to Criptala — another credential worth guarding just as closely as your password and recovery codes. See Account & settings for how to create, whitelist, and revoke them.

On this page