Skip to content

Set up login and registration

Shape how a brand's sign-in and registration screens look, and decide when traders must confirm a one-time passcode to sign in or register.

The Login & Registration tab of the brand editor has two parts: Appearance, which controls the layout and background of the sign-in and sign-up screens, and Sign-in security (OTP), which controls one-time passcode challenges. Every change is applied together when you click Save in the header.

Prerequisites

  • You are signed in to the Backoffice with a role that grants permission to manage brands.
  • You have opened a brand from the brands list and selected the Login & Registration tab.

What traders see

Traders reach these screens on the brand's WebTrader and Client Zone web address. They sign in with their Account ID or email and a password — plus any social sign-in provider you have enabled in Set up brand identity and login. New customers register from the built-in sign-up form, unless you point the brand at an external registration page.

The screens are shown in the layout you choose below. When one-time passcode challenges are on, a trader enters a short code after the password step before they are signed in.

Choose a layout

Under Appearance, pick one of four layouts for the desktop sign-in and registration screens:

  • Split · image — the form on one half of the screen and the brand's background image on the other.
  • Split · QR — the same split, but the image half shows a QR code traders can scan to open the brand's mobile app. This layout needs a Mobile app link (below); until you add one, the layout stays locked and a prompt links you to the field.
  • Flat colour — the form centered on a solid background color, with no image.
  • Glass over image — the form on a translucent "glass" card floating over a full-screen background image.

Mobile derives its own layout

You choose the desktop layout; the mobile layout is derived from it automatically so the two stay consistent. A chip under the picker names the mobile result — for example, a split layout becomes a full-image screen on mobile, and a glass layout keeps its glass card.

If you leave the layout unset, the brand uses a sensible default based on its background: Glass over image when a background image is set, otherwise Flat colour. A caption shows which layout is currently in effect.

Choose the form side

For a split layout, use Form side to put the sign-in form on the left or the right half. The sides are mirrored automatically for right-to-left languages.

In Mobile app link, enter an https link to the brand's mobile app — an app-store page or an app landing page. The Split · QR layout renders this link as the QR code traders scan, and adding a link unlocks that layout. If you clear the link while Split · QR is selected, the brand falls back to the derived layout so a scannable panel is never shown empty.

Set the background

Replace the platform's standard sign-in artwork with the brand's own background — a full-screen image or a flat color — used on desktop and mobile. Watch the walkthrough:

  • Background image — upload a PNG, JPEG, or WebP file up to 5 MB. Images must be landscape (wider than they are tall): at least 1280×720 pixels, with 1920×1080 recommended. Click Remove image to discard it. A dark overlay keeps the sign-in text readable over any image.
  • Stock backgrounds — instead of uploading, pick one of the platform's ready-made background images from the gallery.
  • Background color — enter a CSS color (for example #0A0A0F) to use a flat color instead. The image and the color are mutually exclusive: setting one clears the other.

Leave both empty to keep the platform's standard artwork.

Preview before you save

The Live preview on the right repaints from your current, unsaved choices so you can see what the WebTrader will render before committing. Flip between Desktop and Mobile, and switch the Screen between Sign in, Create account, and Verify code. The preview is view-only — nothing changes until you click Save.

Require a one-time passcode (OTP)

The Sign-in security (OTP) card controls whether the brand challenges traders for a one-time passcode — a short numeric code sent by SMS or email — during Client Zone sign-in and registration. The platform enforces the mode you choose on the server, so the challenge cannot be skipped from the browser.

Under When to challenge, choose a mode:

  • Off — no one-time passcode challenges; a password alone signs traders in.
  • Registration only — the trader confirms a code once, at registration, to verify their phone. Sign-ins are not challenged.
  • Every login — every interactive sign-in is challenged. A trader who is still signed in on a remembered session is not challenged again mid-session.
  • New device — registrations and the first sign-in from an unrecognized browser are challenged; a device the trader has already verified skips the code. Under this mode, a trader also receives an email when a new device signs in.

Delivery and code rules

The card shows the brand's current Channel (SMS, email, or SMS with email fallback) and code rules — how long a code stays valid, how many attempts each code allows, and the resend cooldown. These values are set in the brand's Client-Zone settings and are shown here for reference.

Spend protection

Because each SMS costs money, the card sets limits that protect against runaway sending:

  • Per-phone daily cap — the most one-time passcode messages sent to a single phone number per day (1–1000). Clear the field to use the platform default.
  • Brand daily circuit-breaker — a hard ceiling on one-time passcode messages for the whole brand per day (1–1,000,000). Clear the field to use the default.
  • Destination-country allowlist — a comma-separated list of two-letter ISO country codes (for example IL,GB,DE) that codes may be sent to. Leave it empty to allow every country.

The allowlist matches the dialled number's own country

Some numbers that share a calling code still have their own country code — for example, a Guernsey mobile on +44 is GG, not GB. If you need to reach those destinations, list their codes explicitly.

Spend limits fail safe

If the platform cannot confirm that a message is within these limits, it does not send the message. Set the caps to values that fit the brand's real sign-in volume so legitimate traders are not blocked.

An SMS preview below the card renders the brand's one-time passcode message with sample data, so you can check the wording and the autofill line before going live.

Standalone trading brands

A standalone trading brand (one whose offering does not include the Client Zone) signs traders in by Account ID and is not challenged for a one-time passcode. For those brands, the OTP card is replaced by a short note and there is nothing to configure here.

Click Save in the header to apply your changes.