Your PortWorth dashboard holds a complete picture of your financial life: shares, property, super, crypto, and cash. A compromised account could expose that picture to anyone. Two-factor authentication (2FA) and passkeys make it significantly harder for an attacker to access your account, even if your password is stolen.
This guide covers three things: enabling 2FA with an authenticator app, adding a passkey (Face ID, Touch ID, or Windows Hello) for fast biometric login, and sharing a read-only view of your portfolio with a financial adviser.
All security settings live in your profile, not the main dashboard settings panel.
TOTP stands for Time-based One-Time Password. It's the 6-digit code that rotates every 30 seconds in your authenticator app. PortWorth supports any standard TOTP app including Google Authenticator, Authy, 1Password, Bitwarden, and Apple's built-in Passwords app.
Once enabled, every login will require your password followed by the 6-digit TOTP code. The code changes every 30 seconds, so even if an attacker captures your password, they cannot log in without physical access to your phone.
Passkeys are a newer, stronger alternative to passwords. They use public-key cryptography and are bound to your device. They can't be phished, guessed, or stolen in a data breach the way passwords can. Once you add a passkey, you can use it instead of your password for future logins.
| Device | Authentication method |
|---|---|
| iPhone / iPad | Face ID or Touch ID |
| Mac | Touch ID |
| Android | Fingerprint or Face Unlock |
| Windows | Windows Hello (PIN, fingerprint, or face) |
| YubiKey | FIDO2 hardware key |
You can register multiple passkeys. For example, one on your iPhone and one on your MacBook. Each passkey is listed on the Security tab with its name and registration date. Remove any passkey at any time if the device is lost or sold.
PortWorth lets you share a read-only view of your portfolio with your financial adviser without giving them access to your account. The link is time-limited, requires no login on their end, and can be revoked at any time.
Adviser share links show a curated read-only snapshot. PortWorth has designed the access level to be useful for your adviser's work without exposing sensitive personal or banking data.
Your adviser can see:
Your adviser cannot see:
Advisers have no ability to edit data, record trades, move funds, or make any changes. The share link is view-only at the portfolio level.
If you decide to close your PortWorth account, the option is in your profile settings.
Use one of the backup codes you saved when setting up 2FA to log in, then set up a new authenticator app on your replacement device. If you've also lost your backup codes, contact PortWorth support for identity-verified account recovery. This process may take several business days to complete.
No. Adviser share links provide read-only access. Your adviser can view holdings and performance but cannot edit data, execute trades, or access your banking or vault.
You choose the expiry when creating the link: between 1 and 30 days. The default is 7 days. Links automatically expire and cannot be extended; create a new link if your adviser needs continued access.
Passkeys work alongside your password. They don't replace it at the account level. You can log in using either method. We recommend keeping a strong password as a fallback and using your passkey as the primary login on trusted devices.
It depends on the app. Authy syncs across devices automatically. Google Authenticator has account-sync via a Google account. 1Password syncs via your 1Password vault. If you use a local-only app, set it up on both your phone and a backup device, or store backup codes in your password manager.
Our team typically responds within one business day.