Skip to main content
An account that runs automation rules across live ad spend is worth protecting properly. The Security page covers both halves of that: adding a second factor to your sign-in, and keeping an eye on the devices already signed in. Reach it from Profile → Security, or directly at /profile/security.

Two-factor authentication

With two-factor authentication on, your password alone is no longer enough to sign in — you also enter a time-based code. TheOptimizer supports two methods, and you can use either or both.
Registers your email address to receive time-based codes at sign-in.
1

Open Email Authentication

Click Email Authentication on the Security page.
2

Confirm your email and password

Enter the email address that should receive codes, then your account password.
3

Send the code

Click Send Code. If it does not arrive, Resend Code sends another.
4

Enter the 6-digit code

Type the code from the email and click Verify.

Managing verified devices

Every authenticator app you link appears as its own device, showing the browser it was registered from, when it was added, and the IP address it was registered from. You can rename a device by clicking its name — useful once you have more than one. Deleting a device asks for your password to confirm, and is only possible once you have more than one linked, so you can never lock yourself out by removing the last one.
Link a second authenticator app — on a tablet, or a second phone — before you need it. It costs a minute now and saves a support ticket if your primary phone is lost or replaced.

Activity sessions

Activity Sessions lists every place your account is currently signed in. Each entry shows:
  • The device and browser
  • When it was last active
  • The IP address it connected from
Your current session is marked so you don’t end it by accident. Logout All appears once you have more than one active session, and asks you to confirm before it runs.
Two habits worth keeping: end sessions on shared or client machines when you’re finished with them, and after changing your password, use Logout All so anyone holding the old one is pushed out.