Account security
Two-factor, backup codes, the devices signed in as you, and the way back if you lose your phone.
Your AffiliateRail account can generate a payout batch and holds the PayPal or Wise credentials that money leaves through. Everything on this page exists because of that one fact.
Everything here is in the dashboard under Settings, Security.
Two-factor
A six-digit code from an authenticator app, on top of your password. It is optional to turn on and required before a payout batch moves, which is the middle ground: nobody is forced into it while they are still deciding whether to buy, and nobody sends other people's money with a password alone.
Settings, Security, Turn on two-factor. You type your password first, so somebody who found your screen unlocked cannot do this.
Scan the square with an authenticator app: 1Password, Google Authenticator, Authy, whatever you already use. If you cannot scan, the same secret is printed beside it to type in by hand.
Type the six digits the app shows. Nothing is switched on until this matches, so an app that was not set up properly cannot lock you out.
Save the ten backup codes. This is the only time they are shown. Put them in your password manager, not in your email.
From then on, signing in asks for your password and then the code. If you sign in with Google or Apple, you are asked for the code there too.
Backup codes
Ten of them, each good once. The Security tab shows how many are left, and using one sends you a note saying it happened. When you are running low, New backup codes replaces the whole set: the old ten stop working the moment the new ten appear, so save them before you close the page.
Turning it off
Off needs your password and a current code, never one or the other. A stolen session that also knows the password is exactly the case a second factor exists for, so one of the two is not enough to remove it.
Before a payout batch moves
Two things ask you to confirm it is you:
- generating or sending a payout batch,
- adding, testing or removing a payout connection.
If two-factor is on, you type a code. The confirmation lasts fifteen minutes and belongs to the browser you are in, so approving three batches in a row is one code, not three, and a browser somebody else is holding gets none of it.
If two-factor is not on, you are asked to set it up there and then, with the reason on the screen. It is the moment it matters.
Devices signed in as you
The Security tab lists every browser with a live session on your account: what it looks like, roughly where it signed in from, when it started and when it was last used. The one you are reading this in is marked.
Sign this one out ends a single session at once. Sign out of every other device ends all of them and leaves you signed in here.
Two honest limits. The device is whatever the browser says it is, so two laptops running the same browser on the same operating system read the same. The location is worked out from the network address and is approximate: a city that looks wrong usually means your internet provider, not somebody else.
Recent activity
Sign-ins, failed attempts, password changes and every change to your second factor, newest first, with the device and rough location beside each one. This is the first place to look if something feels off, and it is worth a glance after any email from us about your account.
If you lose your phone
With your backup codes: sign in as usual, choose Use a backup code instead, and type one. Then turn two-factor off and on again on the new phone, which gives you a fresh set of ten.
Without your backup codes: there is still a way back, and it deliberately does not depend on your email address, because your email is the thing an attacker is most likely to have.
On the code screen, choose There is a way back in, then sign in with your email and password. A recovery can only be started by somebody who knows your password.
We show you a TXT record. Publish it on your website's domain, wherever you bought the domain. Control of that domain is the identity check, and it is something you can do at three in the morning without waiting for anybody.
Press I have published it. DNS usually takes a few minutes.
Wait 72 hours. Your codes keep working the whole time, we tell the address on your account what is happening, and one press cancels it. This wait is the point: a recovery that happens instantly is a second front door.
Come back, sign in with your password, and two-factor comes off. Set it up again on the new phone straight away.
If your program has no website on file, or you no longer control the domain, write to support@affiliaterail.com from an address at your company's own domain. The same waiting period applies.
If you get an email saying a recovery was started and it was not you, cancel it from that email or from the Security tab, then change your password. A recovery cannot be started without it.
Emails you will get from us
Turning two-factor on or off, replacing your backup codes, using a backup code, signing out a device, and signing in from a device we have not seen before each send a note to the address on your account. They come from affiliaterail.com and not from your own sending domain, so a broken DNS record can never silence them, and they are never affected by unsubscribing from anything.
Partners
Partners sign in to the portal with a link sent to their email and hold no password and no payout credential of yours, so there is no second factor on that side. Their own payout details are encrypted at rest and are never shown back to you or to us in full.
What is not here
Single sign-on and SAML are an Enterprise conversation rather than a switch in this tab. If you need them, say so when you talk to us.