Tradovate

Tradovate 2FA Lockout: Lost Authenticator, No Backup

You wiped your old phone, and the authenticator that guards your login went with it. There's no backup method, and no code will get you in. Here's the real fix, and how to make sure one lost phone never locks you out again.

Vérifié par l'équipe Trading Systems de PickMyTrade Dernière mise à jour
· 7 min read
Tradovate login screen prompting for a two-factor authentication code with no alternative verification option

You wiped your old phone, switched to a new one, and only now realize your authenticator app didn't come with it. The login screen wants a six-digit code you can't produce, there's no “email me a code instead” link, and you never set a backup method. Your account, your balance, maybe an open position, all sit behind a wall you built yourself.

It's a bad feeling, but it's a solvable one. This isn't a hacked account or a corrupted login. It's a verification gap, and there are exactly two things that matter now: getting back in, and making sure you never end up here again.

Short version: If you're already locked out with no backup method, you can't fix this from the login screen. Contact Tradovate customer service, verify that you own the account, and ask them to reset your two-factor authentication. Once you're back in, turn on at least two 2FA methods and register a trusted device so a single lost phone can't do this again.

Why a lost authenticator locks you out completely

Two-factor authentication works by demanding something you know (your password) plus something you have (a code from your authenticator, a security key, a trusted device, or an SMS). That second factor is the whole point. It's supposed to stop anyone who steals your password from getting in.

The catch is that the system can't tell the difference between an attacker who doesn't have your second factor and you after you've lost it. From the login screen's side, both look identical: correct password, no valid code. So it does exactly what it's designed to do and refuses entry. There's no secret bypass, and honestly you wouldn't want one, because a bypass would defeat the entire security model.

Tradovate login screen prompting for a two-factor authentication code with no alternative verification option

When you enabled 2FA, you likely picked a single method, an authenticator app, and skipped past the prompt to add a backup. That's the trap. A time-based one-time password app like Google Authenticator stores its secret key on the device itself. Unless you backed that key up or migrated it, wiping or losing the phone erases it for good. The codes it generated are gone, and there's no way to regenerate them without the original secret.

Step 1: Confirm what you actually still have

Before you assume the worst, take two minutes to check whether any working method survives. People forget they set more than one. Any of the following can get you in without a support ticket:

  • A trusted device. If you previously marked a browser or computer as trusted, logging in from that exact machine may skip the code prompt entirely. Try your usual desktop first.
  • A second authenticator install. Some people scan the 2FA QR code into two apps or two phones. Check any older device or a password manager that stores TOTP codes.
  • A security key. If you registered a hardware key (USB, NFC, or a passkey saved in your password manager or Windows Hello), plug it in and use it.
  • SMS. If you ever enabled text-message codes, the login flow may let you request one to your phone number.

If even one of these works, log in and jump straight to the prevention section below to fix your setup properly. If none of them do, you're genuinely locked out and it's time to contact support.

Step 2: Contact Tradovate customer service to reset your 2FA

This is the real fix when you have no backup. A human on Tradovate's side can verify your identity and reset the two-factor setting on your account, which drops you back to password-only login long enough to reconfigure things. Here's how to reach them:

Tradovate customer support contact options including in-app live chat, phone, and email
Channel How to use it Best for
In-app live chatAvailable to Tradovate customers inside the platform (and on the website help widget)Fastest first contact if you can reach any signed-in surface
Phone1 (844) 283-3100Urgent lockouts, especially with an open position
Email[email protected]Non-urgent cases and attaching identity documents
Support portalsupport.tradovate.comSubmitting a ticket and tracking the response

When you reach out, make their job easy. Tell them up front that you've lost your only 2FA method and need it reset. Have your account details ready, the email tied to the account, your account username or ID, and whatever identity confirmation they ask for. Expect them to verify you're the owner before they touch anything. That verification step is a feature, not an obstacle. It's the same protection that's currently keeping a stranger out.

Open position while locked out? Say so in your very first message and lead with it on the phone. Market risk doesn't pause while a ticket sits in a queue. If you have any other signed-in device or platform still connected to the account, use it to manage or flatten the position while support works on the reset.

One reassurance: a 2FA reset doesn't wipe anything. Your balance, trade history, risk settings, and order records all stay exactly as they were. The only thing that changes is how you prove it's you at the door.

Prop firm and evaluation accounts work differently

If you're logging into a prop firm evaluation or funded account, the reset path may not run through Tradovate at all. Many of those accounts are owned and administered by the firm, and the firm, not Tradovate, controls access recovery. Two-factor requirements, who can reset them, and how long it takes all vary by firm and account type, so check your firm's current rules and open a ticket with them first. Trying Tradovate directly on a firm-owned account usually just bounces you back to the firm anyway.

Step 3: Set up backup 2FA methods so this can't happen again

Once you're back in, don't just re-add a single authenticator and walk away. That's how you end up right back here after your next phone upgrade. Tradovate lets you run several verification methods at once, and the whole idea is redundancy: lose one, fall back to another.

Head to your Application Settings and open the security area. On that page you'll find the two-factor toggle and, below it, the options to add additional verification steps.

Tradovate Application Settings security page showing the two-factor authentication toggle and enabled methods

Tradovate supports four kinds of second factor, and I'd enable at least two of them:

Method What it is Why it helps as a backup
Authenticator appA TOTP app such as Google Authenticator that generates rotating six-digit codesWorks offline; pick one that supports cloud backup or export so a lost phone isn't fatal
Security keyA hardware key over USB, NFC, or Bluetooth, a passkey in a password manager, or Windows HelloPhysical and phishing-resistant; hard to lose if it lives on your keyring or in your manager
Trusted deviceA browser or machine you've marked as known and authenticatedLets your everyday computer skip the code prompt, so a lost phone doesn't strand you
SMS codeA one-time code texted to your phone numberA simple fallback tied to your number rather than a specific app install

To add a hardware or passkey option, look for the section that lets you add extra verification steps (labeled along the lines of “Add additional verification steps”) and choose to add a security key. The platform walks you through registering it. Exact wording and menu labels shift between platform updates, so if a label on your screen doesn't match word for word, look for the closest equivalent under the same security settings and follow the on-screen prompt.

Tradovate security settings section for adding a security key and managing trusted devices

Scroll to the bottom of the security page and you'll also find your list of trusted devices, which you can view and manage there. Register the computer you actually trade from. That single step means that even if your phone vanishes tomorrow, your desktop still gets you in while you sort out a replacement authenticator.

A few habits that keep you out of trouble

  • Migrate before you wipe. When you replace a phone, move or re-add your authenticator to the new device before you factory-reset the old one. This is the single most common way people lock themselves out.
  • Use an authenticator with backup. Some TOTP apps sync an encrypted backup to the cloud or let you export your seeds. That turns a lost phone into a minor annoyance instead of a support ticket.
  • Keep your account email current. Recovery and verification lean on the email tied to your account. If it's an old address you can't open, fix that first.
  • Store recovery details offline. If you're issued any backup or recovery information, write it down and keep it somewhere physical and safe, not only inside the same phone that holds your authenticator.

What about the "new machine" 2FA prompt?

Worth separating two things people mix up. Losing your authenticator with no backup is one problem. Getting a “you have 2FA enabled and are logging in from a new machine” message is a different, milder one. In that second case you usually still have access; Tradovate just emails a device-approval link you need to confirm before the new device can trade. If that's actually your situation, check your inbox (and spam) for the approval email rather than assuming you're locked out.

And if your trouble is really the login screen hanging, a failing captcha, or a temporary lock after too many wrong attempts, those have their own fixes, don't assume it's a 2FA problem until you've ruled those out.

Don't Let a Login Screen Stall Your Strategy

Once you're back into your account, PickMyTrade automates your Tradovate orders straight from TradingView, so entries and exits fire on signal instead of waiting on you to be logged in and watching.

Start Your Free 5-Day Trial

Frequently Asked Questions

Yes, but not on your own. With no working second factor and no backup configured, the login screen has no way to verify you. Your only path is to contact Tradovate customer service, prove you own the account, and ask them to reset the 2FA. There's no self-service button for this.

Trusted devices, security keys, authenticator apps that generate time-based one-time passwords like Google Authenticator, and SMS codes. Enable more than one so losing a single method doesn't lock you out.

No. A reset only changes how you verify your identity at login. Your balance, history, and settings stay put. If you're holding a position while locked out, flag it as urgent in your first message so support prioritizes it.

It depends on who owns the account. Many evaluation and funded accounts belong to the prop firm, which handles access issues rather than Tradovate. Rules and reset steps vary by firm and account type, so check your firm's current rules and open a ticket with them first.

Enable at least two verification methods, register the computer you trade from as a trusted device, and store any recovery information somewhere safe and offline. When you switch phones, move or re-add your authenticator before wiping the old one.

This guide is for educational and informational purposes only and is not financial, investment, or trading advice. Trading futures and other leveraged products carries a substantial risk of loss and is not suitable for every investor. PickMyTrade is an independent third-party automation platform and is not affiliated with, endorsed by, or sponsored by Tradovate, Inc. or Bookmap. All related names, logos, and trademarks are the property of their respective owners. Platform features and steps change over time, so always confirm the current process in the official platform documentation before acting.