Account
Account Security
Two-factor authentication with an authenticator app, and how your Amazon credentials are stored and used.
Account Security
Two-factor authentication
Two-factor authentication adds a code from an authenticator app on top of your password. It is optional, and strongly recommended if your Rufusly account is connected to your Amazon seller account.
Turning it on
- Open Settings and go to the Security tab
- Start the setup and scan the QR code with your authenticator app
- Enter the 6-digit code the app shows to confirm it
Any TOTP app works: Google Authenticator, 1Password, Authy, and others. If your app cannot scan a QR code, the setup screen also shows the secret so you can type it in.
What changes afterwards
Nothing changes for anyone who has not turned it on. Once you have confirmed an authenticator, every sign-in asks for the 6-digit code before you reach the dashboard.
If you lose your phone
Register a second authenticator on another device while you still have access to the first. That is the recovery path, and it is worth doing on the day you set 2FA up.
If you are already locked out with no second authenticator registered, email support@rufusly.ai and we will verify you and reset the factor.
You can remove an authenticator at any time from the same Security tab.
How your Amazon credentials are handled
Your Amazon SP-API credentials are encrypted at rest using AES-256 before they are stored. They are decrypted server-side only, at the moment a call to Amazon is made, and they are never returned to the browser.
The same applies to any other connection secret you save in Rufusly, including your own Anthropic API key.
You can disconnect Amazon at any time from Settings, then Connections. Disconnecting removes the stored credentials from Rufusly. If you want the access itself revoked, do that in Seller Central as well.
Practical advice
- Turn on 2FA on your Amazon Seller Central account too. Rufusly cannot protect an account that is already compromised at Amazon
- Give each MCP client its own API key, so you can delete one without breaking the rest
- Delete API keys you no longer use. Keys are shown once at creation and stored only as a hash, so a lost key cannot be recovered, only replaced
Frequently asked questions
Does Rufusly support two-factor authentication?
Yes. Rufusly supports two-factor authentication with any TOTP authenticator app, set up from the Security tab in Settings by scanning a QR code and confirming the 6-digit code. It is optional, and once enabled every sign-in asks for the code.
What happens if I lose the phone with my Rufusly authenticator on it?
Register a second authenticator on another device while you still have access to the first, which is the intended recovery path. If you are already locked out with no second authenticator, email support@rufusly.ai and we will verify you and reset the factor.
Does Rufusly offer backup codes for two-factor authentication?
No. Rufusly does not issue backup codes. Recovery is either a second registered authenticator or a support-verified reset, so register a second device when you first enable two-factor authentication.
How does Rufusly store my Amazon seller credentials?
Amazon SP-API credentials are encrypted at rest with AES-256, decrypted server-side only when a call to Amazon is made, and never returned to the browser. You can disconnect Amazon from Settings, then Connections, at any time to remove them.
Do I have to enable two-factor authentication on Rufusly?
No, it is opt-in. If you never enrol an authenticator, sign-in is unchanged. It is strongly recommended if your Rufusly account is connected to your Amazon seller account.