Skip to content
Back to Site

Security

Add a passkey, manage your password and two-factor authentication, review account connections, and inspect recent login activity.

Security protects account access and provides the controls needed to manage passkeys, passwords, two-factor authentication, connected login providers, and recent sign-ins.

  • Sign in to the correct Next-Cart account.
  • Make sure you can access the account email.
  • Use a device, browser profile, or security key that you control before adding a passkey.
  • Keep your authentication device or a valid Backup Code available for protected changes.
  • Before disconnecting a social account, confirm that another sign-in method will remain available.
ControlUse it to
PasskeysSign in securely with Face ID, Touch ID, Windows Hello, or a security key.
PasswordChange the account password.
Two-Factor AuthenticationAdd or remove a second verification step.
Account ConnectionsConnect or disconnect Google, Apple, or Facebook.
Login ActivityReview recent sign-in dates, IP addresses, devices, locations, and status.
  1. Open Security

    Go to Account → My Account → Security.

  2. Select Add Passkey

    Under Passkeys, select Add Passkey.

  3. Complete the device or browser prompt

    Approve the requested Face ID, Touch ID, Windows Hello, or security-key verification.

  4. Confirm the passkey

    Return to Security and confirm that the Passkeys area no longer shows No passkeys added yet.

  1. Open Security

    Go to Account → My Account → Security.

  2. Start the password change

    Select Change Password.

  3. Enter the new password

    Enter the new password and confirm it.

  4. Save the change

    Complete the password change and review the confirmation message.

The password must meet these requirements:

RequirementRule
Length8 to 128 characters
NumberAt least 1 number
Uppercase letterAt least 1 uppercase letter
WhitespaceNo leading or trailing whitespace

After a successful password change, Next-Cart sends an email notification and signs out other active sessions.

For your security, other active sessions have been signed out.

Use 2FA to require a second verification method during sign-in and protected account changes.

  1. Select Enable 2FA

    Open Security and select Enable 2FA.

  2. Verify your identity

    Sign in again when requested.

  3. Complete the setup

    Follow the verification instructions shown during activation.

  4. Save the Backup Codes

    Copy or download the 8 Backup Codes and store them securely.

Each Backup Code works once. Keep the codes outside the device used for two-factor authentication.

Select Regenerate, verify your identity with the current 2FA method or a valid Backup Code, then save the new set. The previous codes become invalid.

Select Disable 2FA, sign in again, complete the current 2FA or Backup Code verification, and confirm the change.

You can connect one Google account, one Apple account, and one Facebook account to the Next-Cart account.

  1. Choose a provider

    Under Account Connections, select Connect for Google, Apple, or Facebook.

  2. Authorize the connection

    Sign in to the social account and follow the provider prompts.

  3. Complete verification when required

    If the social email differs from the Next-Cart account email, verify the connection through the primary account email.

  4. Confirm the connection

    Return to Security and confirm that the provider is connected.

A social account already connected to another Next-Cart account cannot be connected again until it is disconnected from the original account.

Select Disconnect, confirm the request, and verify your identity. Next-Cart prevents disconnection if it would leave the account without a usable sign-in method.

Login Activity shows the 10 most recent login attempts.

DetailWhat to reviewExample
DateWhen the login occurredJan 21, 2026 5:33 PM
IP addressThe IPv4 or IPv6 address used113.161.3.3
DeviceBrowser and device or operating systemChrome on Windows
LocationEstimated city and countryHanoi, Vietnam
StatusWhether the attempt succeeded or failedSuccess or Failure

Review unfamiliar activity immediately, especially successful logins from an unexpected device, location, or IP address.

After completing a Security task:

  • the intended passkey is registered on a controlled device or security key;
  • the intended password or 2FA status is active;
  • current Backup Codes are stored securely;
  • only approved social accounts remain connected;
  • recent login activity is recognizable or investigated.
CheckPass condition
PasskeyThe Passkeys area confirms that a passkey has been added, and the device or security key is controlled by an authorized user.
PasswordThe new password works and other active sessions were signed out.
2FAThe expected second verification step appears during sign-in.
Backup CodesThe current set is stored securely and old regenerated codes are no longer used.
Account ConnectionsOnly authorized Google, Apple, and Facebook accounts are connected.
Login ActivityRecent successful logins match expected users, devices, locations, and IP addresses.
IssueWhat to do
You cannot sign inUse Forgot password during sign-in or an already connected social account.
Add Passkey does not completeCancel the prompt, confirm that the browser, device unlock method, or security key is available, then try again. Record the browser, device, and visible error before contacting Support.
The new password is rejectedCheck the length, number, uppercase, and whitespace requirements.
The 2FA device is unavailableUse one unused Backup Code.
Backup Codes are unavailableContact Support and prepare to verify account ownership.
A social account is already linked elsewhereSign in to the account that currently uses it and disconnect it there first.
Disconnect is blockedSet a password or connect another sign-in method before disconnecting the only available method.
Login Activity is unfamiliarChange the password, review Account Connections, regenerate Backup Codes, and contact Support if the activity may be unauthorized.