Help Centre Security & 2FA

Two-Factor Authentication, Passkeys & Adviser Access.

Security guide· ~5 min read· All plans
General information only. PortWorth is a wealth tracking tool, not a financial adviser. Nothing in this guide constitutes financial advice. Always consult a qualified professional before making investment decisions.

Why securing your account matters

Your PortWorth dashboard holds a complete picture of your financial life: shares, property, super, crypto, and cash. A compromised account could expose that picture to anyone. Two-factor authentication (2FA) and passkeys make it significantly harder for an attacker to access your account, even if your password is stolen.

This guide covers three things: enabling 2FA with an authenticator app, adding a passkey (Face ID, Touch ID, or Windows Hello) for fast biometric login, and sharing a read-only view of your portfolio with a financial adviser.

Step 1: Open Security Settings

All security settings live in your profile, not the main dashboard settings panel.

  1. Log in to PortWorth and click your name or avatar in the top-right corner of the dashboard.
  2. Select Profile from the dropdown menu.
  3. Click the Security tab at the top of the Profile page. Here you'll see your current 2FA status, any registered passkeys, and your active sessions.

Step 2: Enable TOTP (authenticator app)

TOTP stands for Time-based One-Time Password. It's the 6-digit code that rotates every 30 seconds in your authenticator app. PortWorth supports any standard TOTP app including Google Authenticator, Authy, 1Password, Bitwarden, and Apple's built-in Passwords app.

  1. Click Enable Two-Factor Authentication on the Security tab. A QR code will appear.
  2. Open your authenticator app and scan the QR code. The app will add a PortWorth entry showing a rotating 6-digit code.
  3. Enter the 6-digit code currently shown in your app and click Confirm. This verifies that your app is synced correctly.
  4. Copy your backup codes. PortWorth will display a set of one-time backup codes. Save these somewhere safe: a password manager, encrypted note, or a printed sheet in a secure physical location. You'll need these if you ever lose access to your authenticator app.
Save your backup codes somewhere safe: a password manager or printed copy in a secure location. If you lose your authenticator app and don't have backup codes, account recovery requires identity verification and may take several business days.

Once enabled, every login will require your password followed by the 6-digit TOTP code. The code changes every 30 seconds, so even if an attacker captures your password, they cannot log in without physical access to your phone.

Step 3: Add a Passkey (Face ID / Touch ID / Windows Hello)

Passkeys are a newer, stronger alternative to passwords. They use public-key cryptography and are bound to your device. They can't be phished, guessed, or stolen in a data breach the way passwords can. Once you add a passkey, you can use it instead of your password for future logins.

Tip Passkeys are more secure than passwords and can't be phished. If your device supports Face ID, Touch ID, or Windows Hello, we recommend adding a passkey as your primary login method.
  1. On the Security tab, click Add Passkey.
  2. Your browser or OS will prompt you to authenticate with your device's biometrics or PIN. Approve it. This creates the passkey and stores it securely on your device (or in iCloud Keychain / Google Password Manager for cross-device access).
  3. Give the passkey a name if prompted (e.g. "iPhone 16 Pro" or "MacBook") so you can identify it later if you need to remove it.
  4. Test your passkey by logging out and back in. Select "Sign in with a passkey" on the login screen and approve the biometric prompt.

Passkey compatibility

Device Authentication method
iPhone / iPadFace ID or Touch ID
MacTouch ID
AndroidFingerprint or Face Unlock
WindowsWindows Hello (PIN, fingerprint, or face)
YubiKeyFIDO2 hardware key

You can register multiple passkeys. For example, one on your iPhone and one on your MacBook. Each passkey is listed on the Security tab with its name and registration date. Remove any passkey at any time if the device is lost or sold.

Step 4: Share your portfolio with an adviser

PortWorth lets you share a read-only view of your portfolio with your financial adviser without giving them access to your account. The link is time-limited, requires no login on their end, and can be revoked at any time.

  1. Go to Settings from the main dashboard menu.
  2. Click Adviser Access in the settings sidebar.
  3. Click Create Share Link. Choose an expiry between 1 and 30 days. The default is 7 days.
  4. Copy the generated link and send it to your adviser via email or your usual communication channel.
  5. Your adviser opens the link in any browser. No PortWorth account or login is required.
  6. To revoke access early, return to Adviser Access and click Revoke next to the active link. The link stops working immediately.

Step 5: What advisers can and cannot see

Adviser share links show a curated read-only snapshot. PortWorth has designed the access level to be useful for your adviser's work without exposing sensitive personal or banking data.

Your adviser can see:

  • Current holdings and allocations across all asset classes
  • Net worth over time (the performance chart)
  • Performance metrics: total return, P&L, XIRR
  • AI-generated portfolio reports (if you have enabled them)

Your adviser cannot see:

  • Bank account numbers or BSB numbers
  • Tax file number
  • Documents in the Vault tab
  • Banking transaction history
  • Your login credentials, passkeys, or 2FA settings

Advisers have no ability to edit data, record trades, move funds, or make any changes. The share link is view-only at the portfolio level.

Step 6: Delete your account

If you decide to close your PortWorth account, the option is in your profile settings.

  1. Go to Settings, then Profile, and scroll to the bottom of the page.
  2. Click Delete Account. You'll be asked to confirm by typing your email address.
  3. Export your data first if you want a copy of your holdings and trade history. Use the Export button on the relevant tabs before confirming deletion.
  4. Once confirmed, your account is queued for deletion. All data is purged from PortWorth servers within 30 days, including holdings, trade history, and personal information.

Frequently asked questions

What happens if I lose access to my authenticator app?+

Use one of the backup codes you saved when setting up 2FA to log in, then set up a new authenticator app on your replacement device. If you've also lost your backup codes, contact PortWorth support for identity-verified account recovery. This process may take several business days to complete.

Can my financial adviser make changes to my portfolio?+

No. Adviser share links provide read-only access. Your adviser can view holdings and performance but cannot edit data, execute trades, or access your banking or vault.

How long does an adviser share link last?+

You choose the expiry when creating the link: between 1 and 30 days. The default is 7 days. Links automatically expire and cannot be extended; create a new link if your adviser needs continued access.

Can I use a passkey without also having a password?+

Passkeys work alongside your password. They don't replace it at the account level. You can log in using either method. We recommend keeping a strong password as a fallback and using your passkey as the primary login on trusted devices.

Is my 2FA code synced across devices?+

It depends on the app. Authy syncs across devices automatically. Google Authenticator has account-sync via a Google account. 1Password syncs via your 1Password vault. If you use a local-only app, set it up on both your phone and a backup device, or store backup codes in your password manager.

Questions about your account?

We're here to help.

Our team typically responds within one business day.