Overview
Account safety is a top priority at MoonPay. This guide explains how to use two-factor authentication (2FA), App Lock, and device management to keep your account secure.
Key benefits
Stronger sign-in protection: 2FA adds an extra layer of security to protect your account even if someone gains access to your email or password
Faster, safer access in the MoonPay mobile app: App Lock helps protect your account with biometric authentication or a device PIN
More control over account access: Device management lets you review devices and remove ones you don’t recognize or use
Two-factor authentication (2FA)
What is 2FA?
Two-factor authentication (2FA) adds an extra layer of security to your MoonPay account. This requires you to verify your identity using two different methods— protecting you even if someone gains access to your email or password.
How 2FA works at MoonPay
MoonPay supports the following 2FA methods:
Password: A password you can create to access your account via the MoonPay App
Email OTP: A one-time code sent to your registered email address
SMS OTP: A one-time code sent to your verified phone number via text message
2FA for login
When you sign in to MoonPay, you may be required to complete 2FA based on your account's security settings.
Password users: If you sign in with a password, you'll receive an email verification code as your second factor when logging in from a new or unverified device
2FA for sensitive actions
Certain sensitive actions require additional verification. When you perform these actions, you'll receive a verification code via SMS or email that you must enter to proceed.
This step-up authentication ensures that even if someone gains access to your active session, they cannot complete high-risk actions without access to your verification method.
Setting up SMS 2FA
When creating an account or signing in to an existing account without a phone number, you are required to enter and verify your phone number. This will be used for some sensitive actions going forward.
Important: If you no longer have access to your registered phone number or email, contact our support team for assistance via the chat button at the bottom right of this page.
App Lock with biometric authentication
To help protect your account and make accessing the MoonPay app faster and more secure, we’ve introduced App Lock using biometric authentication.
What is App Lock?
App Lock automatically locks your MoonPay app after:
You close or swipe away the app, or
You’re inactive for more than 5 minutes
When this happens, you’ll need to re-authenticate using Face ID, Touch ID, or your device PIN to access the app again.
How it works
Sign in to the MoonPay app
When prompted, set up biometric authentication to enable App Lock
Use biometrics (or your device PIN) to unlock the app whenever it locks
Important: App Lock is mandatory — you must select either biometric authentication or a device PIN to continue using the app.
Note: You can change your App Lock method in Settings → Security.
How this improves security
Your biometric data is stored securely on your device; it is never processed by MoonPay or stored on MoonPay servers
This helps protect your account even if someone gains access to your unlocked phone
App Lock helps prevent unauthorized use of your MoonPay account while balancing security and convenience
Adjust the timeframe required to authenticate
To help keep your account secure, our app automatically locks after 5 minutes of inactivity or when you close it completely.
This means you’ll be asked to authenticate (using biometrics or your device PIN) the next time you open the app.
To adjust the auto-lock timeframe:
Open the app
Go to Settings → Security
Choose the auto-lock timing that works best for you
Disable biometric authentication
Yes — you can turn off biometric authentication (Face ID, Touch ID, or similar) at any time. To disable biometrics:
Open the app
Go to Settings → Security
Toggle biometric authentication off
Note: Disabling biometrics may make your account more vulnerable to unauthorized access, especially if your device is lost or stolen. For your security, we strongly recommend keeping biometric authentication enabled.
Important:
App Lock is enabled per device — if you log in on a new phone, you’ll be asked to set it up again
If biometric authentication is disabled at the device level, App Lock will also be disabled in the app
If biometric authentication fails, you can use your device PIN as a fallback
Device management
What is device management?
Device management gives you visibility and control over the devices that have accessed your MoonPay account. You can view your devices and remove any that you no longer recognize or use.
Why device management matters
Track account access: See which devices have logged into your account
Detect unauthorized access: Identify unfamiliar devices that may indicate compromised credentials
Revoke access instantly: Remove a device to immediately end all active sessions on that device
View your devices
Sign in to your MoonPay account
Go to Settings → Security → Devices
View the list of devices that have accessed your account
Remove a device
If you see a device you don't recognize, or if you've lost a device:
Go to Settings → Security → Devices
Find the device you want to remove
Tap Remove
What happens when you remove a device:
All active sessions on that device are immediately ended
The person using that device will need to sign in again
New device notifications
When you sign in from a new device, you'll receive an email notification with details about the sign-in.
Important: If you don't recognize a sign-in, we recommend removing the unfamiliar device from your account immediately.
How to update your email address
You can update your email address in a few steps. Here's how:
Sign in to your MoonPay Account with your registered email address
Go to Settings → Account → click Edit in the email address section
Enter the 6-digit code sent to your current email address
Enter the code to proceed
Once verified, enter the new email address for your MoonPay account
That’s it! You will receive an email confirmation once it has been updated.
Important: You cannot update to an email already linked to another active MoonPay account.
If you didn’t receive the email verification code
Email codes are sent directly to the email address you enter. If you haven't received the email verification code, make sure you entered the correct email address and check your junk and spam mail folders.
If you can’t find the email, contact your email provider for support.
Note: Email codes may take a few seconds to arrive — wait at least 5 seconds before requesting a new one.
Security best practices
Keep App Lock enabled with biometric authentication for convenient yet secure access
Add a verified phone number to enable SMS 2FA for sensitive actions
Review your devices regularly and remove any you don't recognize
Act on new device notifications immediately if you see unfamiliar sign-ins
Use a strong, unique password if you've enabled password-based login
Keep your email and phone number up to date to ensure you can receive verification codes
Need help? Contact our support team via the chat button at the bottom right of this page.
