Account security
Your admin login guards real money and your customers' details, so it gets its own page in the admin: open Security in the sidebar. Everything here is about your own account, split across two tabs — Password for changing your password, and Multi-factor setup for multi-factor authentication (MFA). Managing your team's logins lives in Team users.
Until MFA is set up, the Security item in the sidebar carries a small warning triangle. That's deliberate nagging: a password alone is one phishing email away from being someone else's password. Clicking the nagged item lands you straight on the Multi-factor setup tab.
Changing your password
On the Password tab, fill in your current password and the new one, then save with the bar at the top. A new password needs at least 12 characters with an uppercase letter, a lowercase letter, a numeral, and a symbol, and Platypus refuses passwords that have turned up in public breaches — the same bar every login on your venue has to clear. The change applies immediately: you stay logged in on this device, and every other device still signed in as you is logged out the next time it does anything.
If you've forgotten your password, use Forgot password? on the login page instead — the emailed reset link stays valid for 3 days.
Setting up multi-factor authentication
MFA adds a second step to logging in: a six-digit code from an authenticator app on your phone (Google Authenticator, Microsoft Authenticator, 1Password, Aegis — anything that speaks TOTP).
- On the Security page's Multi-factor setup tab, confirm your password and choose Set up authenticator app.
- Scan the QR code with your app (or type in the setup key shown under it).
- Enter the six-digit code the app shows and choose Confirm and activate.
MFA is not active until you confirm. If you wander off halfway, nothing changes, and you can start again later.
Recovery codes
The moment you confirm, Platypus shows a set of recovery codes — one-time passwords for the day your phone is lost, dead, or in a taxi. They are shown only once. Store them somewhere that isn't the phone: a password manager or a printed page in a drawer.
Each code works exactly once at the login screen. To replace them, confirm your password and choose Generate new recovery codes on the Multi-factor setup tab; every code in the old set stops working the moment the new set appears.
Logging in with MFA
After MFA is active, logging in asks for your email and password as usual, then for the current code from your authenticator app. Lost the device? Choose Lost your device? Use a recovery code on that screen and spend one of your recovery codes instead.
Turning MFA off
On the Multi-factor setup tab, confirm your password under Turn off multi-factor authentication. Logins go back to password-only, and the sidebar warning returns. The old QR code stops working; setting MFA up again later generates a fresh secret.
Locked out completely?
If you've lost both the authenticator device and your recovery codes, contact Platypus support. An operator can clear MFA on your account (the action is logged in your venue's audit trail), after which you log in with your password and can re-enrol from the Security page. Your password itself can always be reset by email from the login page, so no one else who uses your admin can lock you out of your own account.