Account Settings Overview
Your Pocketsflow account settings control your profile, security, and business identity. Access them at Settings → Account.Profile Information
Basic Details
Manage your account identity and how you appear to customers: Available Settings:| Field | Description | Requirements |
|---|---|---|
| Name | Your full name or business name | Required, displayed on receipts |
| Username | Unique identifier for your creator page | 3-30 characters, alphanumeric + hyphens |
| Primary contact email | Must be verified | |
| Avatar | Profile image | JPG/PNG, max 5MB |
| Bio | Short description | Optional, 500 characters max |
| Location | City, Country | Optional |
- Go to Settings → Account
- Update any field
- Click Save Changes
- Verify email if changed (check inbox for confirmation link)
Username Requirements
Your username appears in your creator page URL:pocketsflow.com/@username
Rules:
- ✅ 3-30 characters
- ✅ Letters, numbers, hyphens allowed
- ✅ Must be unique across Pocketsflow
- ❌ No spaces or special characters
- ❌ Cannot start/end with hyphen
Authentication & Login
Auth0 Integration
Pocketsflow uses Auth0 for secure authentication with OAuth 2.0: Features:- Passwordless login via email magic links
- Social login (Google, GitHub, etc.)
- Automatic session management
- Secure refresh token rotation
- Go to Settings → Account → Login Methods
- See connected authentication providers
- Add or remove login methods
- Update password (if using email/password)
Password Best Practices
If using password authentication: ✅ DO:- Use a unique password (not reused elsewhere)
- Make it 12+ characters with mixed case, numbers, symbols
- Use a password manager (1Password, Bitwarden, etc.)
- Update immediately if compromised
- Share your password with anyone
- Use common passwords (“Password123”)
- Reuse passwords from other sites
- Write it down in insecure locations
- Settings → Account → Security
- Click Change Password
- Enter current password
- Enter new password (twice)
- Click Update Password
Two-Factor Authentication (2FA)
Coming Soon: 2FA support is planned for a future release. Check the roadmap for updates.
- Use authenticator app (Google Authenticator, Authy, 1Password)
- Save backup codes securely
- Test logging in with 2FA before closing session
- Keep backup method (SMS) as fallback
- Protects against password theft
- Required for high-value accounts
- Prevents unauthorized access even if password leaks
- Industry best practice for financial platforms
Session Management
Active Sessions
View and manage logged-in devices: Where to check:- Settings → Account → Active Sessions
- See device type, browser, location, last active
- Sign out - Remove specific device
- Sign out all devices - Force re-login everywhere (recommended if compromised)
- Review sessions monthly
- Sign out from unknown devices immediately
- Avoid public/shared computers
- Use private browsing on shared devices
Session Timeouts
Automatic logout:- Inactive for 30 days - automatic session expiration
- Invalid token - immediate logout with redirect to login
- Rate limit exceeded (429) - temporary lockout
Security Best Practices
Protect Your Account
Recognizing Phishing
Pocketsflow will NEVER:- ❌ Ask for your password via email or support ticket
- ❌ Request your API keys or webhook secrets
- ❌ Send suspicious links from non-pocketsflow.com domains
- ❌ Demand immediate action to “verify” account
- ❌ Ask for payment outside the dashboard
- Emails from @gmail.com, @outlook.com (not @pocketsflow.com)
- Spelling errors or poor grammar
- Generic greetings (“Dear User”)
- Urgent threats (“Account will be closed”)
- Links to non-pocketsflow.com domains
- Don’t click any links
- Forward to security@pocketsflow.com
- Delete the email
- Change password if you entered credentials
Account Recovery
Lost Access
If you can’t log in: Email-based recovery:- Click Forgot Password on login page
- Enter your account email
- Check inbox for reset link (check spam)
- Click link and set new password
- Log in with new password
- Contact support@pocketsflow.com
- Provide account verification:
- Username
- Last 4 digits of connected bank account
- Recent transaction details
- Support will verify identity and assist
Account Compromise
If your account was hacked:Contact support
Email security@pocketsflow.com with details
Test Mode vs Live Mode
Pocketsflow operates in two modes to protect live data:Test Mode
Purpose: Safe environment for development and testing Characteristics:- ⚙️ Separate database from live
- 💳 Use payment gateway/PayPal test credentials
- 🔄 No real money or transactions
- 🧪 Perfect for experimenting with products, webhooks, APIs
- 🔍 API keys prefixed with
pk_test_
Live Mode
Purpose: Production environment with real transactions Characteristics:- 💰 Real money, real customers
- ✅ Requires identity verification (KYC)
- 🏦 Connected bank account for payouts
- 🔐 Production API keys (
pk_live_) - 📊 All analytics and reporting
- Complete identity verification
- Connect payment gateway or PayPal account
- Set up bank account for payouts
- Add at least one published product
- Configure tax settings (if applicable)
Identity Verification (KYC)
Why Verification is Required
For regulatory compliance and fraud prevention, Pocketsflow requires identity verification through our payment processor: Required for:- Receiving payouts
- Going live with products
- Processing customer payments
- Full legal name
- Date of birth
- Home address
- Government ID (passport, driver’s license)
- Tax ID / SSN (US) or equivalent
- Bank account details
Verification Process
Status tracking:
- Pending - Submitted, awaiting review
- Processing - Under manual review
- Verified - Approved, can receive payouts
- Requires Input - Additional documents needed
Verification Issues
Common problems:| Issue | Solution |
|---|---|
| ID photo blurry | Retake in good lighting, keep camera steady |
| Name mismatch | Use exact legal name on ID |
| Address doesn’t match | Update to current address on ID |
| Underage | Must be 18+ in most countries |
Account Deletion
Requesting Deletion
To permanently delete your account: Before deleting:- ✅ Export all customer data (Settings → Customers → Export)
- ✅ Download sales reports (Settings → Analytics → Export)
- ✅ Complete pending payouts
- ✅ Inform active subscribers (subscriptions will be canceled)
- ✅ Backup product files and content
- Settings → Account → Delete Account
- Review what will be deleted
- Enter password to confirm
- Click Permanently Delete Account
- Confirm via email link
- Account immediately deactivated
- Customer access revoked within 24 hours
- Data permanently deleted after 30-day grace period
- Payment gateway/PayPal accounts disconnected
- Custom domains released
Security Checklist
Monthly Review
- ✅ Check active sessions, sign out unknown devices
- ✅ Review recent login activity
- ✅ Update password if using same password elsewhere
- ✅ Verify account email still accessible
- ✅ Check for any unauthorized products or settings changes
Immediate Action If Suspicious
- ✅ Change password immediately
- ✅ Sign out all devices
- ✅ Review recent account activity
- ✅ Contact security@pocketsflow.com
- ✅ Check connected bank/payment accounts
Ongoing Protection
- ✅ Use password manager
- ✅ Enable 2FA (when available)
- ✅ Keep email secure
- ✅ Don’t share credentials
- ✅ Verify emails before clicking links
- ✅ Only use official Pocketsflow URLs
Related Topics
Payment Settings
Configure payment gateway and PayPal
Payout Settings
Set up bank account and payouts
API Keys
Manage developer access
Tax Configuration
Set up tax collection