docs
Platform guides

Account security

Two-factor, backup codes, the devices signed in as you, and the way back if you lose your phone.

Your AffiliateRail account can generate a payout batch. It also holds the PayPal or Wise credentials that money leaves through. So it needs more than a password.

Everything here's in the dashboard under Settings, Security.

Two-factor

Two-factor means a second check on top of your password: a six-digit code from an authenticator app on your phone.

  • It's optional to turn on, so nobody is forced into it while they're still deciding whether to buy.
  • It's required before a payout batch moves, so nobody sends other people's money with a password alone.

Go to Settings, Security, Turn on two-factor. You type your password first, so somebody who finds your screen unlocked can't do this. Signed up with Google? There's no password to type. If you signed in more than 15 minutes ago, you choose Continue with Google first instead.

Scan the square with an authenticator app: 1Password, Google Authenticator, Authy, whatever you already use. If you can't scan, the same secret is printed beside it to type in by hand.

Type the six digits the app shows. Nothing is switched on until this matches. An app that wasn't set up properly can't lock you out.

Save the ten backup codes. This is the only time they're shown. Put them in your password manager, not in your email.

From then on, signing in asks for your password and then the code. If you sign in with Google or Apple, you're asked for the code there too.

Backup codes

A backup code gets you in when you don't have your phone. You get ten, and each works once.

  • The Security tab shows how many are left.
  • Using one sends you a note saying it happened.
  • When you're running low, New backup codes replaces the whole set.

The old ten stop working the moment the new ten appear. Save them before you close the page.

Turning it off

Turning it off needs your password and a current code. One of the two isn't enough. If you signed up with Google, you have no password, so it takes the code. Let's say someone steals your session and also knows your password. That's exactly the case a second factor exists for, so without a code they still can't remove it.

Who on your team can do what

Everyone on your team has one of three roles. You pick admin or member when you invite someone, under Settings, Team. There's one owner: the person who made the account. The owner can't be removed.

WhatOwnerAdminMember
See everything in the dashboardYesYesYes
Look after partners: add, review, tag, notes, emails and resourcesYesYesYes
Change the program's name, branding and signup questionsYesYesYes
Remove a partner, or change their group, rate or payout minimumYesYesNo
Approve or decline leads your partners send inYesYesNo
Approve, reject, edit or add commissionsYesYesNo
Make, send, mark paid, change or delete payoutsYesYesNo
Change commission rules, attribution, safeguards and couponsYesYesNo
Add, move or remove customers, or change a customer's emailYesYesNo
API keys, webhook settings, domains, imports, sample data and new programsYesYesNo
Connect PayPal or Wise to pay partnersYesNoNo
Change your plan or card, cancel, or open StripeYesNoNo
Connect PaddleYesNoNo
Invite or remove people on your teamYesNoNo
Ask us to delete a partner's or customer's dataYesNoNo

If your role can't do something, you're told so and nothing changes. On Team and Billing, those buttons don't show at all. The check runs on our server, so it holds even if a button is on the screen.

Before a payout batch moves

These ask you to confirm it's you:

  • generating or sending a payout batch, or turning on automatic payouts
  • marking a payout paid, or deleting one
  • changing what a payout holds: one amount, a percentage across all of it, or taking a commission out
  • adding, testing or removing a payout connection

If two-factor is on, you type a code. The confirmation lasts fifteen minutes, in the browser you're using. Approving three batches in a row takes one code. A browser somebody else is holding gets none of it.

If two-factor isn't on, you're asked to set it up there and then, with the reason on the screen.

Devices signed in as you

The Security tab lists every browser signed in to your account. For each one it shows:

  • what the device looks like
  • roughly where it signed in from
  • when the session started
  • when it was last used

The one you're reading this in is marked.

Sign this one out ends a single session at once. Sign out of every other device ends all of them and leaves you signed in here.

There are two limits:

  • The device is whatever the browser says it is. Two laptops running the same browser on the same operating system look the same.
  • The location comes from the network address, so it's approximate. A city that looks wrong usually means your internet provider, not somebody else.

Recent activity

This list shows sign-ins, failed attempts, password changes and every change to your second factor. It's newest first, with the device and rough location beside each one.

Look here first if something feels off. It's worth a glance after any email from us about your account.

If you lose your phone

With your backup codes: sign in as usual, choose Use a backup code instead, and type one. Then turn two-factor off and on again on the new phone. That gives you a fresh set of ten.

Without your backup codes: there's still a way back. It doesn't depend on your email address on purpose, because your email is the thing an attacker is most likely to have.

On the code screen, choose There's a way back in. Then sign in with your email and password. Only somebody who knows your password can start a recovery.

We show you a TXT record, a line of text you add to your domain's DNS settings. Publish it on your website's domain, wherever you bought the domain. Control of that domain proves it's you. You can do it at three in the morning without waiting for anybody.

Press I have published it. DNS usually takes a few minutes.

Wait 72 hours. Your codes keep working the whole time. We tell the address on your account what's happening, and one press cancels it. The wait stops an attacker getting in straight away.

Come back, sign in with your password, and two-factor comes off. Set it up again on the new phone straight away.

Maybe your program has no website on file, or you no longer control the domain. Then write to support@affiliaterail.com from an address at your company's own domain. The same waiting period applies.

If you get an email saying a recovery was started and it wasn't you, cancel it. Do that from the email or from the Security tab, then change your password. A recovery can't be started without it.

Emails you'll get from us

Each of these sends a note to the address on your account:

  • turning two-factor on or off
  • replacing your backup codes
  • using a backup code
  • signing out a device
  • signing in from a device we haven't seen before

They always come from affiliaterail.com, so a broken DNS record on your own sending domain can never silence them. Unsubscribing from anything never affects them either.

Partners

Partners sign in to the portal with a link sent to their email. They hold no password and none of your payout credentials, so there's no second factor on that side.

Their own payout details are encrypted at rest. They're never shown back to you or to us in full.

What isn't here

Single sign-on (SSO) and SAML let your team sign in through your company's identity provider. There's no switch for them in this tab. They're an Enterprise conversation, so if you need them, say so when you talk to us.