Lock icon representing website account security

How to Secure Your statpx Account: 2FA, Login History, and API Keys

An analytics account contains more sensitive data than it might seem at first. Your traffic patterns reveal when your site is growing or struggling. Your referrer data shows which partnerships and campaigns are working. Your visitor log contains IP addresses and session behavior. None of this should end up in the wrong hands.

statpx provides several tools to help you keep your account secure: two-factor authentication, a full login history log, and API key management with fine-grained control. This guide walks through each one.

Why Account Security Matters for Analytics

Unlike a social media account where the harm of a compromise is obvious, an analytics account breach can be subtle and damaging in ways that aren't immediately visible:

The good news: protecting your account takes under 10 minutes of setup, and statpx makes each step straightforward.

Enabling Two-Factor Authentication (2FA)

Two-factor authentication adds a second verification step to your login. Even if someone gets your password, they can't access your account without also having your authenticator app. This is the single most effective step you can take.

To enable 2FA in statpx:

statpx 2FA setup page with QR code for authenticator app
The statpx 2FA setup page — scan the QR code with any authenticator app

Save your backup codes now. If you lose your authenticator app and don't have backup codes, you cannot recover access to your account. Store backup codes in a password manager — not in a plain text file on your computer.

Signing In with 2FA

Once 2FA is enabled, the login flow changes slightly:

  1. Enter your email and password as usual and click Sign in
  2. A second screen appears asking for your verification code
  3. Open your authenticator app and enter the current 6-digit code shown for statpx
  4. Click Verify — you're in

TOTP codes refresh every 30 seconds. If the code expires while you're typing, just use the next one that appears. Most authenticator apps show a timer so you know when the current code is about to rotate.

If you've lost your authenticator app — phone replaced, app deleted, new device — use one of your backup codes instead of the 6-digit rotating code. Each backup code works once, then it's invalidated. After signing in with a backup code, immediately set up 2FA again with your new device.

Reviewing Your Login History

statpx records every sign-in event to your account. To see it, go to Login History in the sidebar. Each row shows:

statpx login history page showing sign-in events with IP and location
Login history shows every sign-in event with IP, device, and timestamp

Review this list periodically and look for anything unfamiliar: a country you haven't visited, an IP address you don't recognize, a browser or OS you don't use. Any of these can indicate that your credentials were used by someone else.

If you spot suspicious activity, change your password immediately from the Profile page. Then check whether any goals, alerts, or site settings were modified during the period of suspicious access.

Tip: Set your account timezone in your Profile so that login timestamps display in your local time. Login events stored in UTC can be confusing to read — your local timezone makes it much easier to recall whether you were actually at your computer at that time.

Managing API Keys Safely

API keys let you (or your applications) pull analytics data from statpx via the REST API without using your account password. Each key acts as a credential — treat it like one.

statpx API keys management page
API keys page — create and revoke keys, view prefix and last-used date

To create an API key, go to API Keys in the sidebar and click New API Key. Give it a descriptive name — something that tells you which app or script uses it (e.g. "Dashboard widget" or "Monthly report script").

Critical rules for API keys:

You can have up to 5 API keys per account. If you reach the limit, revoke an old one before creating a new one. For a full reference on what you can do with the API, see the statpx REST API guide.

Other Security Best Practices

Beyond 2FA, login history, and API key management, a few additional habits keep your account secure:

If you're part of a team or share site access with others, also review the team access guide to ensure colleagues have appropriate roles rather than full owner credentials. And if you're new to statpx and haven't set up tracking yet, start with the getting started guide.

Start tracking your website for free

statpx gives you privacy-friendly analytics with no cookie banners, no data limits, and no credit card required. Set up takes under 5 minutes.

Get started free →

The Bottom Line

Securing your analytics account is a 10-minute task with lasting returns. Enable 2FA now — it's the most effective single step. Check your login history occasionally to catch anything unusual. Keep your API keys named, minimal, and revoke the ones you don't use. And use team invites instead of shared passwords whenever someone else needs access. Your analytics data reflects the real state of your business; protecting it is worth a small investment of time.

Continue reading

Getting Started
How to Migrate from Google Analytics 4 to statpx: A Step-by-Step Guide
Getting Started
statpx vs PostHog: Which Analytics Tool Is Right for You?
Getting Started
statpx vs Umami: Which Analytics Tool Is Right for You?
Analytics by statpx