Skip to content
Back to Site

Account Security Best Practices

Protect Next-Cart account access and remove temporary migration access responsibly.

Secure account access protects purchases, migration services, connection details, activity, and support records throughout the project.

AreaRecommended practice
PasskeysAdd passkeys only on devices, browser profiles, or security keys controlled by authorized users.
PasswordUse a unique password that is not reused for a source store, target store, or hosting account.
2FAEnable two-factor authentication for accounts that manage purchases or migration services.
Backup CodesStore current Backup Codes securely and outside the primary authentication device.
Account emailProtect access to the email used for verification and recovery.
Account ConnectionsKeep only authorized Google, Apple, and Facebook accounts connected.
Login ActivityReview unfamiliar devices, locations, IP addresses, and failed attempts.

Confirm that:

  • the correct account owns the order and purchased migration service;
  • only authorized users can access the account;
  • registered passkeys belong only to authorized users and controlled devices;
  • the account email can receive verification and support messages;
  • 2FA and recovery methods are available;
  • recent Login Activity does not show unexplained successful access.
  • Do not share passwords, Backup Codes, API tokens, or private keys through ordinary tickets or chat messages.
  • Grant only the access needed to complete connection, migration, validation, or support tasks.
  • Review Login Activity after password, 2FA, email, or Account Connection changes.
  • Use Delegate Access where available instead of sharing the main account sign-in.
Cleanup taskWhy it matters
Revoke temporary API credentialsPrevents unused platform access from remaining active.
Remove KitConnectRemoves the temporary source-store connection package when it is no longer needed.
Rotate temporary store or server passwordsInvalidates credentials shared for migration work.
Review Account ConnectionsConfirms that only authorized social accounts remain connected.
Review Login ActivityConfirms there are no unexpected sign-ins after completion.
Close or update support recordsKeeps the final issue and access state clear.
  1. Change the account password.
  2. Confirm that other active sessions were signed out.
  3. Review Account Connections and disconnect anything unauthorized.
  4. Enable 2FA or regenerate Backup Codes.
  5. Review Login Activity for unfamiliar devices, locations, IP addresses, or failed attempts.
  6. Check Orders, Migrations → My Migrations, Checkout, and Support for unexpected activity.
  7. Contact Support with the affected account email, activity time, device, location, IP address, and relevant migration service.
  • Use Security to change sign-in protection or review Login Activity.
  • Use Settings to change the account email or delete the account.
  • Use Migrations to review purchased migration-service activity.