How are admin sign-ins protected?
Quick answer
Admin panel sign-in uses a one-time code sent to the user's email, or Sign In With Google, with no passwords to steal or reuse. Sessions use short-lived access tokens and refresh tokens that rotate on every use, so a stolen refresh token that is replayed is rejected. API keys are separate, scoped and revocable.
Detailed answer
The panel avoids the most common account risks by not having passwords at all.
Sign-in methods
- Email and one-time code: the code expires quickly and works once.
- Google: Google verifies the email address; PropExecutor checks the token's signature, audience and that the email is verified.
Sessions
- Access tokens carry the firm and the user's role.
- Refresh tokens are stored as secure, HTTP-only cookies.
- Every refresh replaces the refresh token and revokes the old one, so a copied token stops working once the real user refreshes.
Rate limiting
Requests are rate limited, including by IP for unauthenticated routes, which slows guessing attempts.
API keys
- Created per system with chosen scopes.
- The token is shown once.
- Revocable at any time.
Your side
- Protect the email accounts your team signs in with, ideally with two-factor authentication.
- Remove users who leave.
PropExecutor team · Updated
Related questions
- Managing accounts and tradersHow do I sign in to the admin panel?
- How are trader sessions secured?
- The PropExecutor trading terminalWhat happens to a trader's session when I rotate the password?
- Managing accounts and tradersCan I sign in with Google?
- Managing accounts and tradersCan I add team members to the admin panel?
All 11 questions in Security, data and reliability · Every category