Two-factor authentication (2FA)
This FAQ contains the following information:
What is two-factor authentication?
Two-factor authentication (2FA) adds an extra level of security when you sign in to OANDA's trading platforms from either your computer or mobile device. It is designed to prevent unauthorised users from accessing your account with a stolen password.
How does two-factor authentication work?
When enabled, two-factor authentication (2FA) works by requiring an additional login credential every time you try to access your Client Zone account. If you own a smartphone, use any authenticator app (we recommend using Google Authenticator) to generate instant verification codes that are used to sign in to your OANDA account.
After you sign in with your current password, you will be required to request a verification code via your Google Authentication or other application. Once you have the code, you will need to type it when prompted to gain access to your account.
After you have configured your account for 2FA, you will be required to provide the code/unique set of numbers each time you login to your OANDA account.
What is Google authenticator?
Google Authenticator is a mobile application that allows you to generate verification codes on your smartphone without a network connection. Google Authenticator is the best option if you have a smartphone or tablet. Note: authentication can only be configured on one device for each application or service.
-
Google Authenticator is available for Blackberry, iPhone 3+ and Android phones and most tablets. Download the Google Authenticator app from your devices app store.
-
Do not use the 'back' button on your browser during the setup process. If you do, the one-time password won't work and you will be required to rescan the QR code, or resend an email to complete setup.
How to set up two-factor authentication with Google authenticator
Client Zone
-
Log in to the Client Zone page using your email address and password.
-
In the Passwords and security section, go to Two step verification (2FA).
-
In the Client zone section, click on Add device.
-
Scan the QR code using Google Authenticator, enter the code and click on Add.
-
Two-factor authentication is enabled. Click on Close to go back to the Client Zone.
Trading platforms
-
Log in to the Client Zone page using your email address and password.
-
In the Passwords and security section, go to Two step verification (2FA).
-
In the Trading platforms section, click on the toggle button to activate two-factor authentication for trading platforms.
-
Enter the SMS code sent to your registered phone number. Then, click on CONFIRM AND CONTINUE.
-
If the SMS verification is successful, two-factor authentication is enabled.
MT5
To activate 2FA for the MT5 platforms, you must first activate two-factor authentication for the trading platforms in the Client Zone. Once finished, you can use either the MT5 desktop or the MT5 mobile app to activate 2FA for the MT5 platform.
MT5 desktop
-
Log in to the MT5 desktop platform.
-
Scan the QR code using Google authenticator, enter the code and click on Enable 2FA.
MT5 mobile app
-
Log in to the MT5 mobile app.
-
If you see a window on a security issue, click on Bind.
-
On the next window, click on OK.
-
Read and accept the warning. Then, click on OK.
Once successfully bound, you can use the MT5 mobile app as an OTP generator for MT5 desktop and web. To find codes, follow these steps:
-
Go to Settings>Security>OTP.
-
Alternatively, you can click on the menu icon in the top left corner and select your account. Then, click on the shield icon in the top right corner.
-
If not done before, you must set up your validation code.
How to sign in if 2FA is activated
Client Zone
Clients must take the following steps:
-
Log in to the Client Zone using your email address and password.
-
Enter the code from the Google authenticator. Next, click on GO NEXT. This step completes your login and successfully signs you in.
MT5
MT5 desktop
-
On the login window, enter your login, password and the code from the Google authenticator or the MT5 mobile app. Then, click on OK.
MT5 web
-
Select your account on the left.
-
Enter the code from the Google authenticator or the MT5 mobile app. Then, click on Connect to account.
MT5 mobile app
-
On the login window, enter your login, password and the code from the Google authenticator. Then, click on SIGN IN.
How to deactivate two-factor authentication
Client Zone
-
Log in to the Client Zone using your email address and password.
-
In the Passwords and security section, go to Two step verification (2FA).
-
In the Client zone section, click on the toggle button to deactivate Two-factor Authentication.
Trading platforms
-
Log in to the Client Zone page using your email address and password.
-
In the Passwords and security section, go to Two step verification (2FA).
-
In the Trading platforms section, click on the toggle button to deactivate two-factor authentication for trading platforms.
-
Enter the SMS code sent to your registered phone number. Then, click on CONFIRM AND CONTINUE.
-
If the SMS verification is successful, two-factor authentication is disabled.
MT5
To deactivate 2FA for the MT5 platforms, you must deactivate two-factor authentication for Trading platforms in the Client Zone. Once finished, two-factor authentication is disabled for MT5 platforms.
What to do if I no longer have the phone I set up 2FA with?
Contact our customer support for assistance in getting access to your account.