Skip to main content

Enhanced security

Protect your MoonPay account with two-factor authentication (2FA), App Lock, and device management.

Updated this week

Overview


Account safety is a top priority at MoonPay. This guide explains how to use two-factor authentication (2FA), App Lock, and device management to keep your account secure.

Key benefits


  • Stronger sign-in protection: 2FA adds an extra layer of security to protect your account even if someone gains access to your email or password

  • Faster, safer access in the MoonPay mobile app: App Lock helps protect your account with biometric authentication or a device PIN

  • More control over account access: Device management lets you review devices and remove ones you don’t recognize or use

Two-factor authentication (2FA)


What is 2FA?

Two-factor authentication (2FA) adds an extra layer of security to your MoonPay account. This requires you to verify your identity using two different methods— protecting you even if someone gains access to your email or password.

How 2FA works at MoonPay

MoonPay supports the following 2FA methods:

  • Password: A password you can create to access your account via the MoonPay App

  • Email OTP: A one-time code sent to your registered email address

  • SMS OTP: A one-time code sent to your verified phone number via text message

2FA for login

When you sign in to MoonPay, you may be required to complete 2FA based on your account's security settings.

  • Password users: If you sign in with a password, you'll receive an email verification code as your second factor when logging in from a new or unverified device

2FA for sensitive actions

Certain sensitive actions require additional verification. When you perform these actions, you'll receive a verification code via SMS or email that you must enter to proceed.

This step-up authentication ensures that even if someone gains access to your active session, they cannot complete high-risk actions without access to your verification method.

Setting up SMS 2FA

When creating an account or signing in to an existing account without a phone number, you are required to enter and verify your phone number. This will be used for some sensitive actions going forward.

Important: If you no longer have access to your registered phone number or email, contact our support team for assistance via the chat button at the bottom right of this page.

App Lock with biometric authentication


To help protect your account and make accessing the MoonPay app faster and more secure, we’ve introduced App Lock using biometric authentication.

What is App Lock?

App Lock automatically locks your MoonPay app after:

  • You close or swipe away the app, or

  • You’re inactive for more than 5 minutes

When this happens, you’ll need to re-authenticate using Face ID, Touch ID, or your device PIN to access the app again.

How it works

  1. Sign in to the MoonPay app

  2. When prompted, set up biometric authentication to enable App Lock

  3. Use biometrics (or your device PIN) to unlock the app whenever it locks

Important: App Lock is mandatory — you must select either biometric authentication or a device PIN to continue using the app.

Note: You can change your App Lock method in SettingsSecurity.

How this improves security

  • Your biometric data is stored securely on your device; it is never processed by MoonPay or stored on MoonPay servers

  • This helps protect your account even if someone gains access to your unlocked phone
    App Lock helps prevent unauthorized use of your MoonPay account while balancing security and convenience

Adjust the timeframe required to authenticate

To help keep your account secure, our app automatically locks after 5 minutes of inactivity or when you close it completely.

This means you’ll be asked to authenticate (using biometrics or your device PIN) the next time you open the app.

To adjust the auto-lock timeframe:

  1. Open the app

  2. Go to SettingsSecurity

  3. Choose the auto-lock timing that works best for you

Disable biometric authentication

Yes — you can turn off biometric authentication (Face ID, Touch ID, or similar) at any time. To disable biometrics:

  1. Open the app

  2. Go to SettingsSecurity

  3. Toggle biometric authentication off

Note: Disabling biometrics may make your account more vulnerable to unauthorized access, especially if your device is lost or stolen. For your security, we strongly recommend keeping biometric authentication enabled.

Important:

  • App Lock is enabled per device — if you log in on a new phone, you’ll be asked to set it up again

  • If biometric authentication is disabled at the device level, App Lock will also be disabled in the app

  • If biometric authentication fails, you can use your device PIN as a fallback

Device management


What is device management?

Device management gives you visibility and control over the devices that have accessed your MoonPay account. You can view your devices and remove any that you no longer recognize or use.

Why device management matters

  • Track account access: See which devices have logged into your account

  • Detect unauthorized access: Identify unfamiliar devices that may indicate compromised credentials

  • Revoke access instantly: Remove a device to immediately end all active sessions on that device

View your devices

  1. Sign in to your MoonPay account

  2. Go to SettingsSecurityDevices

  3. View the list of devices that have accessed your account

Remove a device

If you see a device you don't recognize, or if you've lost a device:

  1. Go to SettingsSecurityDevices

  2. Find the device you want to remove

  3. Tap Remove

What happens when you remove a device:

  • All active sessions on that device are immediately ended

  • The person using that device will need to sign in again

New device notifications

When you sign in from a new device, you'll receive an email notification with details about the sign-in.

Important: If you don't recognize a sign-in, we recommend removing the unfamiliar device from your account immediately.

How to update your email address


You can update your email address in a few steps. Here's how:

  1. Sign in to your MoonPay Account with your registered email address

  2. Go to SettingsAccount → click Edit in the email address section

  3. Enter the 6-digit code sent to your current email address

  4. Enter the code to proceed

  5. Once verified, enter the new email address for your MoonPay account

That’s it! You will receive an email confirmation once it has been updated.

Important: You cannot update to an email already linked to another active MoonPay account.

If you didn’t receive the email verification code

Email codes are sent directly to the email address you enter. If you haven't received the email verification code, make sure you entered the correct email address and check your junk and spam mail folders.

If you can’t find the email, contact your email provider for support.

Note: Email codes may take a few seconds to arrive — wait at least 5 seconds before requesting a new one.

Security best practices


  • Keep App Lock enabled with biometric authentication for convenient yet secure access

  • Add a verified phone number to enable SMS 2FA for sensitive actions

  • Review your devices regularly and remove any you don't recognize

  • Act on new device notifications immediately if you see unfamiliar sign-ins

  • Use a strong, unique password if you've enabled password-based login

  • Keep your email and phone number up to date to ensure you can receive verification codes

Need help? Contact our support team via the chat button at the bottom right of this page.

Did this answer your question?