Sign In
Help Center / Account Security & Support

Account & Login Support

Security controls, password recovery, and multi-factor authentication for your SSO Develop identity.

1

How to Reset a Forgotten Password

If you have lost access to your password or need to recover your login credentials:

  1. Navigate to the SSO Account Recovery Portal.
  2. Input your registered email address and submit the form.
  3. Check your inbox for the cryptographic password reset email from [email protected].
  4. Click the verification link and set a strong new password (minimum 8 characters with numbers and symbols).
Link expires in 15 minutes Open Password Reset →
2

Account Lockout & Rate Limiting

To defend against credential stuffing and brute-force guessing attacks, our identity gateways enforce strict automated lockout thresholds:

  • 5 Consecutive Failures: The account and requesting IP address are put on a 15-minute cooldown.
  • Automatic Expiration: Once 15 minutes elapse from the last attempt, access is automatically restored.
  • Immediate Unlock: Initiating and completing an authorized password reset verification immediately lifts the lockout.
3

Connecting Social Accounts (Google, Telegram, Facebook, X)

You can streamline your sign-in process by linking your verified identity providers. All OAuth credentials and refresh tokens are encrypted at rest with AES-256-GCM.

Google One-click OIDC OAuth2
Telegram HMAC-SHA256 Widget
Facebook Graph API Auth Link
X (Twitter) OAuth 2.0 with PKCE
4

Emergency Backup Recovery Codes & Account Security

We provide cryptographically verified multi-layer protection and self-service fallback recovery for all accounts:

  • 10 Single-Use Emergency Codes: Download or print your batch of 10 cryptographic backup codes from your Account Dashboard under Security. Each code functions as an emergency single-use authentication token.
  • Self-Service Recovery Portal: If you lose access to your primary device or Passkey, sign in via the Emergency Recovery Portal using your email and any unused backup code.
  • Instant Key Rotation: If you exhaust your recovery codes or suspect exposure, generate a fresh batch inside your dashboard to immediately invalidate all previous recovery codes.
  • Email Magic Link Fallback: You can also request a passwordless, cryptographically signed magic login link delivered directly to your verified inbox via Magic Link Login.
10 one-time emergency tokens per batch Open Recovery Portal →
5

Email Verification & Resend Troubleshooting

When creating an account, an email verification token is delivered to ensure your address is authentic:

  1. Check Inbox & Spam: Open the confirmation link sent by [email protected]. Verification links are cryptographically signed and expire after 24 hours.
  2. Unverified Login Prompt: If you attempt to log in before verifying, the system presents an auth.email_unverified security dialog.
  3. Inline One-Click Resend: Click Resend email right inside the error dialog to request a fresh verification link instantly.
  4. Self-Service Status Page: You can also navigate directly to Verify Email Status and enter your email address.
  5. Anti-Spam Cooldown: To protect mail delivery queues, a 60-second cooldown is enforced between resend attempts for the same recipient.
60-second cooldown per recipient Open Email Verification →
6

Passkeys & Biometric Authentication (FIDO2 / WebAuthn)

Passkeys replace traditional passwords with cryptographic public-key credentials bound to your physical device (Touch ID, Face ID, Windows Hello, or YubiKey):

  • Phishing Immunity: Passkeys are cryptographically bound to sso555.com. They cannot be intercepted, typed into fake websites, or stolen via credential stuffing.
  • How to Register: Sign in to your Account Dashboard, select Security, and click Register New Passkey. Follow your device's biometric prompt.
  • Cross-Device Ecosystem: If you use Apple iCloud Keychain, Google Password Manager, or Bitwarden, passkeys sync securely across all your registered phones and computers.
  • Backup Keys: We recommend enrolling at least two passkeys (e.g. your smartphone and laptop) or keeping your emergency recovery codes safe.
7

Developer Quotas, Fair-Use Limits & Community Support

OpenID Connect identity provider services are 100% free for all developers and applications:

  • Zero Cost & No Credit Card: Full OIDC/OAuth2 compliance, Passkeys / WebAuthn, and client registration are provided at zero cost without subscription fees, commercial licensing, or paywalls.
  • Standard Fair-Use Allocation: Each developer account receives a standard allocation of 5 client applications, 10,000 monthly active users (MAU), and 120 req/min token endpoint rate limits.
  • Soft-Cap Alerts & Transition Grace: If an application approaches standard limits, proactive dashboard notices provide a 14-day transition period rather than cutting off user logins.
  • Free Quota Increases: Developers operating large-scale public applications can submit a quota increase request via our Help Center to expand capacity at no charge.
8

Self-Service Account Deletion (Danger Zone & Soft-Delete)

You maintain total sovereignty over your personal data and account lifecycle:

  1. Sign in to your account at https://sso555.com.
  2. Navigate to Security and scroll to the bottom Danger Zone.
  3. Click Delete Account and confirm your password or passkey.

Upon deletion, all active JWT access tokens and sessions are immediately revoked. In compliance with security auditing requirements, user records enter a 30-day soft-delete retention window before permanent irreversible purging. For social disconnect instructions or formal GDPR erasure requests, view our Data Deletion Instructions.

← View Frequently Asked Questions Contact Support Team →