Documentation

Securing your account

A few simple habits reliably protect your Cordavix account and your Discord servers against unauthorised access.

A strong, unique password

Use a password for your Cordavix account that you do not use anywhere else, with at least 10 characters and a mixture of character types. We check against a list of commonly used passwords during registration, but that is no substitute for good personal password hygiene – a password manager helps a great deal here.

Enable two-factor authentication

Enable two-factor authentication in the "Account → Security" section (TOTP, compatible with the usual authenticator apps). Keep the backup codes shown to you once in a safe place (a password manager or a safe, for example) – without them, if you lose your device, you can only get back into your account via support.

Keep an eye on your sessions

Under "Account → Sessions" you can see all active logins for your account together with the device and an approximate time. If you do not recognise a session, you can end it individually or end all of them at once – in that case you should also change your password immediately.

Never share your Bot Token

Your Bot Token is equivalent to full access to your bot – never pass it on to third parties, do not post it in Discord channels or screenshots, and only ever enter it directly into the field provided for it in the dashboard. If you should accidentally have shared it after all, reset it immediately in the Discord Developer Portal.

Support never asks for passwords or tokens

Our team will never ask you for your password, a two-factor code or your Bot Token by email, Discord message or contact form. If you receive a request like that, it is an attempted scam – please report it to us via the contact form.

Re-authentication for sensitive actions

For particularly sensitive actions (for example changing a token, changing your email address, disabling two-factor authentication or deleting your account) we require you to confirm your login credentials again – even if you are already signed in. That protects you in case someone were to have brief physical access to a logged-in device.

Found a security vulnerability?

If you should discover a security vulnerability in Cordavix, please report it to us responsibly via the contact form (category "Security") rather than making it public. You will find more background on our technical security measures on the security page.