> ## Documentation Index
> Fetch the complete documentation index at: https://help.vellix.host/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

# Account Security

Keeping your account secure is essential to protect your server files, configurations, and players. In this guide, you will learn how to **change your password** and enable **Two-Factor Authentication (2FA)**.

***

## Changing Your Password

For safety, we strongly recommend changing the auto-generated temporary password you received in your welcome email as soon as possible.

### Steps to update your password:

1. Log in to the panel at [panel.vellix.host](https://panel.vellix.host).
2. Click on your profile avatar in the upper right-hand corner (or the account settings icon in the sidebar).
3. Select **"Account Settings"**.
4. Scroll to the **"Change Password"** section.
5. Enter your current password (the temporary one from your email).
6. Enter your new password and confirm it in the field below.
   * *Tip: Use a mix of uppercase, lowercase, numbers, and special symbols.*
7. Click the **"Update Password"** button.

> \[!NOTE]
> Changing your password will log out all other active sessions for safety. You will need to use your new password for any future logins, as well as for your SFTP connection.

***

## Two-Factor Authentication (2FA)

Two-Factor Authentication adds an extra layer of security. Every time you log in, you will be prompted for your username, password, and a dynamic 6-digit verification code generated by an app on your phone.

### Steps to enable 2FA:

1. Navigate to **"Account Settings"**.
2. Locate the **"Two-Factor Authentication"** section.
3. Click the **"Enable"** button.
4. You will see a **QR Code** and a backup recovery key.
5. Open an authenticator app on your phone (such as **Google Authenticator**, **Authy**, or **Microsoft Authenticator**).
6. Scan the QR code using your app.
7. The app will generate a 6-digit code that changes every 30 seconds.
8. Enter the current 6-digit code on the panel to confirm.
9. Click **"Submit"** or **"Enable"**.

> \[!IMPORTANT]
> **Store your recovery keys in a safe, offline place.** If you lose your phone or delete the app, you will need the recovery keys to log in. Without them, you will have to open a support ticket on our Discord server, and our team will need to manually verify your identity before disabling 2FA.

***

## Resetting a Forgotten Password

If you ever forget your password:

1. Visit [panel.vellix.host](https://panel.vellix.host).
2. Click **"Forgot Password?"** on the login card.
3. Enter your account email address and click **"Send Password Reset Link"**.
4. Follow the link sent to your email to configure a new password.
