Two-factor authentication (2FA)
Add an extra layer of security by requiring a verification code in addition to your password.Enabling 2FA
Choose authentication method
Select your preferred method:
- Authenticator app (recommended): Google Authenticator, Authy, 1Password, etc.
- SMS: Receive codes via text message
Set up authenticator app
If using an authenticator app:
- Scan the QR code with your app
- Enter the 6-digit code shown in your app
- Click Verify
Two-factor authentication is now enabled! You’ll need to enter a code from your authenticator app each time you log in.
Using 2FA
When logging in with 2FA enabled:- Enter your email and password
- Open your authenticator app
- Enter the 6-digit code
- Click Verify
You can check “Trust this device” to skip 2FA for 30 days on that device.
Backup codes
If you lose access to your authenticator:- Click Use backup code on the login screen
- Enter one of your saved backup codes
- Immediately set up a new authenticator
Disabling 2FA
To turn off two-factor authentication:- Go to Settings > Security
- Click Disable 2FA
- Enter your password and current 2FA code
- Confirm disabling
Password security
Password requirements
Boosterberg requires passwords to:- Be at least 12 characters long
- Include uppercase and lowercase letters
- Include at least one number
- Include at least one special character
Changing your password
Password reset
If you forgot your password:- Click Forgot Password on the login screen
- Enter your email address
- Check your email for a reset link
- Click the link and create a new password
Password reset links expire after 1 hour for security.
Session management
Active sessions
View all devices where you’re currently logged in:- Device type and browser
- IP address and location
- Last active time
- Current session indicator
Managing sessions
End sessions on other devices:- Go to Settings > Security > Active Sessions
- Review the list of active sessions
- Click Log Out next to sessions you want to end
- Or click Log Out All Other Sessions to end all except current
Session timeout
For security, Boosterberg automatically logs you out after:- 30 days of inactivity
- 7 days on public/shared computers (if selected during login)
Login security
Login notifications
Receive alerts when someone logs into your account:- Go to Settings > Security > Login Alerts
- Enable Email notifications for new logins
- Choose notification preferences:
- All logins
- Unrecognized devices only
- Failed login attempts
Failed login attempts
After 5 failed login attempts:- Account is temporarily locked for 15 minutes
- You receive an email notification
- IP address is flagged for monitoring
Trusted devices
Mark devices as trusted to skip 2FA:- Checkbox during login: “Trust this device for 30 days”
- Manage trusted devices in Settings > Security
- Remove trust from any device anytime
Security monitoring
Activity log
View all account activity:- Login attempts (successful and failed)
- Password changes
- 2FA changes
- Campaign creations and modifications
- Team member changes
- API key usage
Security alerts
Boosterberg monitors for suspicious activity:- Logins from new locations
- Multiple failed login attempts
- Unusual API usage
- Large budget changes
- Bulk campaign deletions
API security
API key management
Secure your API keys:- Generate separate keys for different integrations
- Set appropriate permissions for each key
- Rotate keys regularly (every 90 days recommended)
- Revoke unused keys immediately
API key permissions
Limit what each API key can do:- Read-only: View data only
- Campaign management: Create and edit campaigns
- Full access: All operations
Revoking API keys
If a key is compromised:- Go to Settings > API
- Find the compromised key
- Click Revoke immediately
- Generate a new key if needed
Best practices
Enable 2FA immediately
Enable 2FA immediately
Two-factor authentication is the single most effective security measure. Enable it as soon as you create your account.
Use a password manager
Use a password manager
Password managers generate strong, unique passwords and store them securely. Popular options: 1Password, Bitwarden, LastPass.
Review security settings monthly
Review security settings monthly
- Check active sessions
- Review activity log
- Verify team member access
- Rotate API keys
Never share credentials
Never share credentials
Keep software updated
Keep software updated
- Update your browser regularly
- Keep your operating system current
- Update your authenticator app
Security checklist
Use this checklist to ensure your account is secure:- Two-factor authentication enabled
- Strong, unique password set
- Password manager in use
- Login notifications enabled
- Active sessions reviewed
- Trusted devices list current
- API keys have minimal permissions
- Team member access is appropriate
- Activity log reviewed monthly
- Backup codes saved securely
Reporting security issues
If you discover a security vulnerability:- Do not disclose it publicly
- Email security@boosterberg.com with details
- Include steps to reproduce if possible
- We’ll respond within 24 hours
Boosterberg has a responsible disclosure policy. We appreciate security researchers who report vulnerabilities responsibly.
Next steps
Manage your team
Add members and control access
Control permissions
Manage Facebook permissions