Security
Account protection, two-factor authentication, and security best practices for your Niftipay account.
Why This Matters
Your Niftipay account controls access to payment funds and API keys. A compromised account can result in unauthorised withdrawals, API abuse, or data exposure.
Security Controls
Two-Factor Auth
RequiredMandatory for all withdrawals. TOTP-based via any authenticator app.
API Key Controls
RecommendedScoped API keys per environment. Revoke individually without affecting other keys.
Session Management
AvailableReview and terminate active sessions from Security Settings.
Payout Controls
RequiredPre-configured wallet addresses per currency. Address changes require re-verification.
Transaction Monitoring
AutomaticAutomatic UNDER REVIEW flags for suspicious transactions.
Integration Review
AvailableWebhook secrets are rotatable without downtime. Scope webhooks per integration.
Security / Verification Settings
Two-Factor Authentication (2FA)
2FA is mandatory for all withdrawal operations. You cannot initiate a withdrawal until 2FA is enabled on your account.
Install an authenticator app
Install Google Authenticator, Authy, or any TOTP-compatible app on your mobile device.
Go to Security Settings
Navigate to Settings → Security in the Niftipay dashboard.
Scan the QR code
Scan the QR code shown in settings with your authenticator app.
Enter the verification code
Enter the 6-digit TOTP code from your app to confirm setup.
Save backup codes
Store backup codes securely. These allow recovery if you lose access to your authenticator device.
Best Practices
Use a strong, unique password
Use a password manager to generate and store a unique password for your Niftipay account.
Never share your API key
API keys have the same level of access as your account. Treat them as passwords.
Review session activity
Regularly review active sessions in Security Settings. Log out any sessions you do not recognise.
Report suspicious activity immediately
Contact support immediately if you notice unexpected withdrawal attempts, API usage, or login activity.