Yes. XWMS supports authenticator-based 2FA. When 2FA is active, verification prompts use your authenticator code instead of sending an email code.
powered by amerencio
Supportgroepen
2FA, verificatiecodes, OAuth-waarschuwingen, domeinen, secrets, logs en gevoelige acties.
Yes. XWMS supports authenticator-based 2FA. When 2FA is active, verification prompts use your authenticator code instead of sending an email code.
Verification codes protect account access, OAuth provider connections, account unlock, and sensitive account changes. The required method depends on your account security settings.
No. For verification flows that use the standard account verification helper, XWMS uses the authenticator code when 2FA is enabled and only sends email codes when 2FA is not enabled.
Store client secrets only on your backend or server environment. Never expose a client secret in frontend JavaScript, public repositories, screenshots, or browser-readable configuration.
Rotate the secret immediately from the API client settings, update your server environment, and review recent API activity for unexpected requests.
Domain verification proves that a website is allowed to use a specific XWMS client. This helps prevent untrusted websites from using your OAuth or API setup.
XWMS warns users when an OAuth website is not verified. This helps users understand that the website has not yet completed the XWMS domain verification process.
Yes. XWMS records API request metadata for audit, debugging, usage tracking, and security review. Sensitive values should not be exposed in logs.
Yes. Connected external login accounts can be removed from your account area after account verification when required.
XWMS combines session checks, account unlock, verification codes, 2FA support, provider checks, and audit logging to protect sensitive actions.
Live support
Je moet ingelogd zijn om een supportticket te starten.
InloggenWelkom terug. Start een ticket of laat je vraag achter.
Bekijk Amerencio Studio Ontdek Studio