Security & Access
Secure your Hostinger account with password changes, two-factor authentication, backup codes, API token management, and account activity review in hPanel.
Password, 2FA, SSH keys, API tokens, and active sessions.
Password
Go to Profile in hPanel.
Click Change Password.
Enter your current and new password.
Confirm.
Tip: Use a password manager and pick something long and unique.
Two-factor authentication (2FA)
Requires both your password and a one-time code. Two methods:
Authenticator app — scan a QR code with Google Authenticator or a compatible app; enter codes from the app at login.
Email code — receive a one-time code by email at login.
Enable
Go to Profile → Security.
Enable two-factor authentication and pick the method.
Confirm with a code, then save the backup codes generated during setup.
Backup codes
One-time codes for when you lose access to your authenticator or email.
Warning: Lose both your 2FA method and backup codes and account recovery requires manual intervention. Store backup codes somewhere safe (password manager, offline vault).
New device protection
A separate toggle under Profile → Security that asks for extra verification when a sign-in looks risky (e.g., a new device). Changing it requires confirming your password.
Disable
Profile → Security.
Disable two-factor authentication.
Confirm with your current 2FA code.
SSH keys
See FTP & SSH Access.
API tokens
API tokens give programmatic access via the Public API.
Create
Open the API page in hPanel (hpanel.hostinger.com/api).
Click Generate new token.
Name it.
Copy the token — it's shown only once.
The same page includes MCP configuration for connecting AI assistants and code editors — see Hostinger Connector.
Warning: Treat API tokens like passwords. Never commit them to Git.
Revoke
Delete the token from the same API page. Revoked tokens stop working immediately.
Account activity
Go to Profile → Account activity.
Review recent sign-ins and the devices used.
If anything looks unfamiliar, change your password — that logs you out of all devices except the current one. You can also log out of any device from the list.
Troubleshooting
Unfamiliar login or unexpected changes Change your password (this logs out all other devices), enable 2FA and New device protection, and rotate any API tokens you've issued.
Password-reset email you didn't request Change your password immediately — someone may be probing your account.
Last updated: July 22, 2026
Last updated
Was this helpful?