Two-Factor Authentication (2FA / TOTP)
Two-Factor Authentication (2FA) is a critical identity security layer on BDX.market designed to safeguard buyer and seller accounts, protect store payout balances, and secure sensitive account actions. Based on standard Time-Based One-Time Password (TOTP) protocols, BDX 2FA requires both your standard account password and a dynamic 6-digit passcode generated by an authenticator app on your smartphone (such as Google Authenticator, Authy, 1Password, or Bitwarden).
1. Why Enable Two-Factor Authentication?​
Digital marketplace accounts hold real value—including BDX Wallet balances, store earnings, active orders, and transaction history. Enabling 2FA ensures that even if someone manages to obtain your password, they cannot access your account without your dynamic secondary passcode.
Security Highlights​
- Local QR Generation: QR codes for setup are generated securely on the BDX server without sharing key details with third-party image services.
- Encrypted Keys: Security keys are stored using industry-standard encryption.
- Unconfirmed Setup Safeguard: Initiating 2FA setup without scanning and confirming your first code will not lock you out. 2FA is activated only after you successfully verify your setup with a valid code.
2. How to Set Up 2FA on Your Account​
Setting up 2FA takes under two minutes:
- Install an Authenticator App: Download Google Authenticator, Authy, Microsoft Authenticator, or Bitwarden on your mobile device.
- Go to Account Security Settings: Log in to BDX and navigate to Account -> Security -> 2FA.
- Scan the QR Code: Use your authenticator app to scan the displayed QR code (or manually copy the secret key string into your app).
- Enter Verification Code: Type the current 6-digit code shown in your authenticator app into the verification box on BDX and click Confirm.
- Save Your Recovery Codes: Upon successful confirmation, BDX will display 8 single-use recovery codes. Save these codes in a safe, offline location immediately.
3. Logging In with 2FA​
Once 2FA is activated on your account:
- Enter your registered email address and password on the Login page.
- Upon password verification, you will be prompted for your 6-digit 2FA code.
- Open your authenticator app, locate the BDX entry, and type the current 6-digit code into the prompt.
- Click Verify to complete login.
Clock Synchronization Note​
TOTP passcodes expire every 30 seconds. BDX includes a small clock drift tolerance window to ensure legitimate passcodes are accepted even if your phone's clock is slightly out of sync. If your codes are consistently rejected, ensure your device's system time is set to update automatically via network time.
4. Single-Use Recovery Codes​
When you activate 2FA, BDX generates 8 single-use recovery codes (e.g., XXXXX-XXXXX).
- When to Use: Use a recovery code if your phone is lost, damaged, stolen, or temporarily unavailable.
- How They Work: Each recovery code can be entered in place of a 6-digit 2FA code during login.
- Single-Use Policy: Once a recovery code is used, it is permanently consumed and cannot be reused.
- Regenerating Codes: You can view or generate a new set of recovery codes anytime from your Account Security settings after verifying your password.
5. Disabling 2FA​
If you need to switch devices or turn off 2FA:
- Go to Account -> Security -> 2FA.
- Click Disable 2FA.
- For security, you will be prompted to enter your account password to confirm removal.