Security Settings
Protect your account and trading data.
Why Security Matters
Your MEXC Manager account holds sensitive information:
- API credentials for your exchange accounts
- Trading history and configurations
- Copy trading settings and follower data
- Referral earnings and withdrawal addresses
Proper security practices help protect all of this.
Never share your password or API credentials. We will never ask for your password via email or support channels.
Password Security
Creating a Strong Password
- Length - At least 12 characters
- Complexity - Mix of uppercase, lowercase, numbers, symbols
- Unique - Don't reuse passwords from other sites
- No personal info - Avoid names, birthdays, common words
Changing Your Password
- 1. Go to Settings
- 2. Navigate to Security section
- 3. Click Change Password
- 4. Enter your current password
- 5. Enter and confirm your new password
- 6. Click Update Password
Use a password manager like 1Password, Bitwarden, or LastPass to generate and store strong, unique passwords.
Two-Factor Authentication (2FA)
Add an extra layer of security with 2FA:
Setting Up 2FA
- 1. Go to Settings → Security
- 2. Click Enable 2FA
- 3. Install an authenticator app (Google Authenticator, Authy)
- 4. Scan the QR code with your app
- 5. Enter the 6-digit code to verify
- 6. Save your backup codes securely
Backup Codes
- You receive backup codes when enabling 2FA
- Each code can only be used once
- Store them securely (not on your phone)
- Use if you lose access to your authenticator app
If you lose your phone and backup codes, account recovery is difficult. Always save your backup codes in a secure location.
Session Management
View and manage your active sessions:
Viewing Active Sessions
- 1. Go to Settings → Security
- 2. Scroll to Active Sessions
- 3. See all devices where you're logged in
Session Information
- Device - Browser and operating system
- Location - Approximate location (based on IP)
- IP Address - Connection IP
- Last active - When the session was last used
Revoking Sessions
- Click Revoke to log out a specific session
- Click Revoke All to log out everywhere
- You'll stay logged in on your current device
API Credential Security
Your MEXC API credentials are sensitive:
Best Practices
- Limit permissions - Only enable permissions you need
- No withdrawal - Never enable withdrawal permission
- IP whitelist - Restrict to specific IPs if possible
- Rotate regularly - Generate new keys periodically
- Separate keys - Use different keys for different purposes
How Credentials Are Stored
- API credentials are encrypted at rest
- Decrypted only when needed for trading
- Never exposed in logs or error messages
- You can delete credentials at any time
Account Activity
Monitor activity on your account:
- Login history - All login attempts (success and failure)
- Settings changes - When settings were modified
- API access - When credentials were used
Suspicious Activity
If you notice suspicious activity:
- 1. Change your password immediately
- 2. Revoke all active sessions
- 3. Regenerate API credentials on MEXC
- 4. Enable 2FA if not already enabled
- 5. Contact support if needed
If you suspect your account is compromised, act immediately. The faster you respond, the less damage can be done.
Security Tips
- Use a unique email - Don't use an email shared elsewhere
- Enable 2FA - Adds significant protection
- Check URLs - Always verify you're on the real site
- Don't share - Never share login credentials
- Log out - Log out on shared devices
- Update regularly - Change password periodically
Data Privacy
Your data is protected:
- All data encrypted in transit (HTTPS)
- Sensitive data encrypted at rest
- Minimal data retention policies
- No selling of user data
- See our Privacy Policy for details