> For the complete documentation index, see [llms.txt](https://zerotick-trade.gitbook.io/documentation.v1.2/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://zerotick-trade.gitbook.io/documentation.v1.2/user-guides/security-settings.md).

# Security settings

Two cards in **Account & Security** set the guardrails on your money: **Security limits & 2FA triggers** sets your spending caps and chooses when a two-factor code is asked for, and **Instant Buy amount** sets how much each one-press buy spends. This guide covers both.

{% hint style="info" %}
Both cards live in **Account & Security**, opened from the profile menu at the top right of the navbar. The two 2FA triggers only take effect once two-factor authentication is on, so set that up first. See [Two-factor authentication](https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/two-factor-authentication).
{% endhint %}

#### Security limits & 2FA triggers

This card holds two withdrawal switches and three US dollar limits. Its subtitle reads "When 2FA is on, choose when it's required. Limits apply across all chains.", so each dollar limit you set is enforced on every supported chain, measured per buy or trade, rather than as a separate limit for each chain.

![The Security limits and 2FA triggers card with its withdrawal switches and dollar limits](https://raw.githubusercontent.com/ZeroTick-Trade/Public-Assets/2e6995eabfe14239fd7ead6ac3785fe21c7dc747/docs/guides/account-and-security/security-settings/01-security-limits-card.png)

| Control                                 | Default  | What it does                                                                                                                                        |
| --------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Require 2FA on every withdrawal**     | On       | With 2FA enabled, every withdrawal to an external address asks for a code before it sends, whatever the amount. Sends to your own wallet never ask. |
| **Lock withdrawals to saved addresses** | Off      | Withdrawals may go only to an address in your saved list. Any other destination is blocked before signing. This applies whether or not 2FA is on.   |
| **Require 2FA for trades above (USD)**  | No limit | With 2FA enabled, a buy or sell worth more than this asks for a code before it runs. Leave it blank for no threshold.                               |
| **Max buy (USD)**                       | No limit | The largest US dollar value a single buy may spend. A larger buy is refused. This applies whether or not 2FA is on.                                 |
| **Max trade (USD)**                     | No limit | The largest US dollar value a single sell or cross-chain trade may reach. A larger trade is refused.                                                |

{% hint style="warning" %}
Leaving **Require 2FA on every withdrawal** on is strongly recommended. It is on by default and is your main check against an external send you did not intend; turning it off removes the code prompt from every withdrawal.
{% endhint %}

**Change your limits**

{% stepper %}
{% step %}
**Open Account & Security**

Open the profile menu at the top right of the navbar and press **Account & Security**.
{% endstep %}

{% step %}
**Open the Security limits & 2FA triggers card**

Scroll to the **Security limits & 2FA triggers** card.
{% endstep %}

{% step %}
**Choose your withdrawal rules**

Use the two switches: **Require 2FA on every withdrawal** and **Lock withdrawals to saved addresses**. Each takes effect on your next withdrawal.
{% endstep %}

{% step %}
**Set your caps and trade threshold**

Type US dollar amounts into **Require 2FA for trades above (USD)**, **Max buy (USD)**, and **Max trade (USD)**. Leave a field empty to switch that limit off; empty fields read **No limit**.
{% endstep %}

{% step %}
**Save**

Press **Save**. If 2FA is on, the **Confirm with 2FA** dialog opens; enter a 6-digit code and press **Confirm** to apply the change.

{% hint style="success" %}
The button briefly reads **Saved** and a **Security settings saved** confirmation appears. Your limits apply from the next buy, trade, or withdrawal.
{% endhint %}
{% endstep %}
{% endstepper %}

<details>

<summary>A field shows "No limit". What does that mean?</summary>

The field is empty, so that control is off. An empty **Max buy (USD)** or **Max trade (USD)** means the amount is not capped, and an empty **Require 2FA for trades above (USD)** means no trade size triggers a code. Type a value to switch the control on; clear the value to switch it back off.

</details>

<details>

<summary>I turned on a 2FA trigger but I am still not asked for a code</summary>

The two 2FA triggers, **Require 2FA on every withdrawal** and **Require 2FA for trades above (USD)**, only work once two-factor authentication is enabled on your account. Set it up first, then the triggers you turned on start prompting. See [Two-factor authentication](https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/two-factor-authentication). The spending caps and the saved-address lock work with or without 2FA.

</details>

<details>

<summary>My buy or trade was refused for being too large</summary>

You reached one of your caps: **Max buy (USD)** for a buy, or **Max trade (USD)** for a sell or a cross-chain trade. This is a hard block, not a prompt. To allow a larger amount, raise or clear the cap on this card and press **Save**; while 2FA is on, that change asks for a code.

</details>

<details>

<summary>Where do I manage saved withdrawal addresses?</summary>

The **Lock withdrawals to saved addresses** switch uses the list on your wallet page. Open Portfolio, go to the Wallet page, and use the "Your withdrawal Wallet(s)" list to add, rename, or remove a saved destination. The full flow is covered in [Withdraw](https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/withdraw).

</details>

#### Instant Buy amount

This card sets the US dollar amount that every Instant Buy spends. Its description reads "The USD amount each Instant Buy spends, in the chain’s native token. Instant Buy fires immediately, with no confirmation." One saved amount is used by every Instant button across ZeroTick.

![The Instant Buy amount card, where you set the USD amount each one-press buy spends](https://raw.githubusercontent.com/ZeroTick-Trade/Public-Assets/2e6995eabfe14239fd7ead6ac3785fe21c7dc747/docs/guides/account-and-security/security-settings/02-instant-buy-card.png)

{% hint style="warning" %}
Instant Buy sends a real market buy the moment you press the button: no amount to type, no review, no undo. Save an amount you are comfortable spending in a single press.
{% endhint %}

{% stepper %}
{% step %}
**Open the Instant Buy amount card**

In **Account & Security**, scroll to the **Instant Buy amount** card. Pressing an Instant button while no amount is saved also opens this card and highlights it.
{% endstep %}

{% step %}
**Enter an amount in USD**

Type the US dollar amount into the field. Amounts are whole dollars from $1 to $100,000; a value outside that range is adjusted to the nearest limit when it saves.
{% endstep %}

{% step %}
**Click away to save**

The amount saves when you click out of the field. To switch Instant Buy off, clear the field: with no saved amount, every Instant button opens this card instead of trading.
{% endstep %}
{% endstepper %}

For where the Instant buttons are and how a one-press buy works, see [Instant trade](https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/instant-trade).

<details>

<summary>Do my security limits apply to Instant Buy?</summary>

Yes. Instant buys obey the same **Security limits & 2FA triggers** as any other trade: a buy above your **Max buy (USD)** cap is refused, and with a 2FA trade threshold set, a larger instant buy still asks for a code.

</details>

These settings control how much a single order can spend and how quickly an Instant Buy is placed; they do not guarantee a price, a fill, or an outcome. Read the [Risk & Legal Disclaimer](https://zerotick-trade.gitbook.io/documentation.v1.1/risk-and-legal-disclaimer) before you trade.

#### Related guides

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Two-factor authentication</strong></td><td>Set up 2FA and backup codes, and see when ZeroTick asks for a code.</td><td><a href="https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/two-factor-authentication">https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/two-factor-authentication</a></td></tr><tr><td><strong>Instant trade</strong></td><td>One-click market buys at your saved Instant Buy amount.</td><td><a href="https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/instant-trade">https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/instant-trade</a></td></tr><tr><td><strong>Withdraw</strong></td><td>Send funds to an external address, with the 2FA and saved-address checks.</td><td><a href="https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/withdraw">https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/withdraw</a></td></tr></tbody></table>
