> For the complete documentation index, see [llms.txt](https://docs.verifone.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.verifone.com/support-us/payware-connect/password-resets/store-portal/store-portal-security-and-password-policy.md).

# Store Portal Security & Password Policy

Security measures, password expiration policy, and MFA requirements for the Store Portal.

## What is the Store Portal's security policy?

The Store Portal uses a session timeout, multifactor authentication (MFA), and a password expiration policy to keep your account and data secure.

## Security measures

* You are logged out after 10 minutes of inactivity in the Store Portal.
* The Store Portal offers Multifactor Authentication (MFA). Once a user is set up after their first sign-in, they must use MFA every time they log in.
* The MFA/OTP lockout count is 3 — you get 3 attempts to validate an OTP. Failing to validate locks the OTP for 30 minutes. If a user fails 3 attempts to validate the OTP on the MFA page, they're locked out and must unlock their account before their next attempt. If 3 login attempts fail, the account locks and Verifone must be contacted at 1-800-837-4366.

## Password expiration policy

Passwords must be changed every 90 days, or they expire.

{% hint style="info" %}
If your password has expired, you can still log in using your old credentials. After logging in, you'll be directed to the Reset Password screen to create a new password. Once reset, log in with the new credentials.
{% endhint %}

## Related topics

* [Signing In with Multifactor Authentication (MFA)](/support-us/payware-connect/password-resets/store-portal/signing-in-with-multifactor-authentication-mfa.md)
* [Resetting Your Password](/support-us/payware-connect/password-resets/store-portal/resetting-your-password.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.verifone.com/support-us/payware-connect/password-resets/store-portal/store-portal-security-and-password-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
