Skip to content

Signing in safely

Your Bottle account can raise invoices in your business’s name. Two things are worth doing.

Under Login & Security, turn on two-step sign-in. You pick one of two ways:

  • An authenticator app on your phone. Strongest: somebody who reads your email still cannot get in. You also get backup codes, for a flat battery.
  • Codes by email. Nothing to install, and weaker, because anybody who can read your email can sign in. Your address must be confirmed first.

Whichever you pick is the only one sign-in will accept afterwards.

Also under Login & Security. This is what colleagues see against work in the app, and what customers see on the paperwork.

Press Change password and the boxes appear. It asks for your current password, and signs out every other device.

Press Change address, give the new one and your password.

We email a link to your current address, not the new one. Your address changes when you follow that link, and not before. The old address is told once it has.

If a confirmation arrives and you did not ask for it, ignore the link and change your password. Somebody else has a way into your account.

We email everyone who can manage the business when:

  • an API key is created or revoked
  • two-step sign-in is turned on, or off
  • a password is changed
  • somebody asks to change the sign-in address, and again once it changes

If one of those arrives and it was not you, somebody else is in the account. Change your password from the sign-in page straight away, and tell us.

Only one of those carries a link: the confirmation for a new sign-in address, which you asked for. Any other email from us with a link in it is not from us.