Skip to main content
Altcraft Docs LogoAltcraft Docs Logo
User guide iconUser guide
Developer guide iconDeveloper guide
Admin guide iconAdmin guide
English
  • Русский
  • English
Login
    User documentationGetting StartedFAQAltcraft glossary
      Profiles and databasesarrow
    • Subscription resourcesManaging databasesSubscriber profileProfiles import and data updateCommon Errors When Importing ProfilesScheduled customer data importManaging Data TablesAutomatic data collectionBulk customers profiles updateDouble opt-in subscriptionSuppression listsProfile relationsProfile history exportProfile exportCreating a static segment based on import resultsHow to open a CSV fileMatchingTypes of fields in the databaseGlobal control groupsSubscription Manager
      Communication channelsarrow
      • Email channelarrow
      • Email: ISP interactions best practices
          First mailingarrow
        • Quick StartEmail
        Email: sending domain configurationEmail: setting up and using postmastersHow email tracking works
        Push Channelarrow
        • Mobile Pusharrow
        • First Mobile Push Mailing
            Mobile Push Providersarrow
          • Firebase Cloud MessagingApple Push Notification ServiceHuawei Mobile ServicesRuStoreYandex.AppMetrica
          Integrate your app with Altcraft
            Deprecated: Manual Push Setuparrow
          • Deprecated: Setup and ConnectionProcessing and adding a subscriptionEvent registrationProviders: push message structure
          Web Pusharrow
        • First Web Push MailingResource and Website Setup
            Web Push Providersarrow
          • Firebase Cloud messagingApple SafariMozilla Services
          Transferring Data to the PlatformWeb Push SDK MethodsPWA and Push Notifications
            Migration and Subscription Transferarrow
          • Migrating push subscriptions from third-party servicesHow to transfer push subscriptions configured for Safari?Migration from OneSignal
        SMS channelarrow
      • SMS
      WhatsAppViber*™
        Telegramarrow
      • Telegram BotTelegram Group
        Maxarrow
      • MAX BotMAX Group
      NotifyCommunication Channels WorkflowРуководство: SMS-рассылка через VK NotifyРуководство: SMS-рассылка через УТШРуководство: push-рассылка через сервис от "Согласие"
      Segmentationarrow
    • Static SegmentsDynamic SegmentsUpdatable Segments
        Segmentation Conditionsarrow
      • Segmentation by Profile dataSegmentation by Interactions with EntitiesSegmentation by Activity of the channel
          Segmentation by external dataarrow
        • Segmentation by external dataSegmentation by external SQL tablesRecommendations for segmentation by external data
        Segmentation by Profile structure
      Best Send Time (BST)Logical operators "AND" and "OR"Recommendations for working with segments
      Message templatesarrow
      • Working with message templatesarrow
      • Working in the editorEmail templateSMS templatePush templateMAX templateTelegram templateWhatsApp templateViber templateNotify template
        Visual editor for email-templatearrow
      • Visual editor interfaceAdding blocksElements and their settingsCustom blocksStyle managerLayer manager
      Template fragmentsImage galleryContent personalizationCreating tables based on array elementsBlock editor for email template
        Altcraft Variables and Functionsarrow
      • Logical expressions in messagesLoops in messagesMarket variables in templatesUsing the JSONPath functionality
        Dynamic content in messagesarrow
      • Dynamic HTML contentDynamic JSON contentContent from SQL database in templatesDynamic API content
      Importing and exporting a message templateImporting a template from a third-party serviceExporting a template from Pixcraft
      Mailingsarrow
    • Broadcast mailingsTrigger mailingRegular mailingMultivariate testingPlacement mailingMailing testingMailing scheduleMailings calendarManaging the Sender Queue
      Automation scenariosarrow
    • Managing scenariosNodes of the scenarioClassic marketing scenariosStep-by-step welcome scenario guideScenario for automatic notification of the managerAbandoned cart scenarioCycle Handling in Automation ScenariosHigh-priority scenarios
      Campaignsarrow
    • Working with CampaignsLocal control groups (LCG)Stratification violation error when limit is reachedAudience expansion in campaignsAudience building
      Marketarrow
    • Market settings
        Productsarrow
      • How to create a product manuallyHow to import a product from a fileScheduled product importProduct and SKU SegmentsPreparing the YML file
      OrdersMarket variables in message templateGuide: how to send an order confirmation email
      Loyalty programsarrow
    • Loyalty programsLoyalty integration with external systemsCreating a loyalty program from scratchBasic loyalty program use casesOrder SegmentsPromotion codes
      Reports and analyticsarrow
    • Channel reportTraffic report
        Summary reportarrow
      • Summary report metrics
      Cohorts reportLifetime reportFunnels reportGoals reportAudience growth reportClick map reportLoyalty programs reportBounces reportUndeliveries reportReport on global control groups
      Integrationsarrow
      • Action hooksarrow
      • Altcraft Action HooksAction hooks event typesAction Hook Message StructureJSON batch request (HTTP POST action hook)Message to RabbitMQ brokerMessage to RabbitMQ exchangerMessage to Kafka brokerTest event
        Integration of third-party services using Albatoarrow
      • Connecting Altcraft to Albato Launching the welcome scenario using AlbatoTransmitting event dataSetting up a trigger mailingEvent registrationGoogle Sheets and Altcraft integration AmoCRM and Altcraft integration
      Facebook Ads Manager™Google Ads AudiencesMAXYandex.Audience™VK AdsStatic segment synchronizationYandex AppMetrica™Tilda™Lpgenerator™WhatsAppViber integrationIntegration scopeData Transmitted During SynchronizationNotify
      Weblayersarrow
      • Formsarrow
        • Create a formarrow
        • General settingsForm customization with custom codeForm constructorAppearanceActions and form publicationConditional logic in forms and surveys
        Data analyticsBinding data channel and formsNPS testing
        Pixelsarrow
      • Goal customer actions and scoring
        Pop-upsarrow
      • Creating and publishing a pop-upSetting up a popup in the code editorManaging pop-ups manually via scriptPopup analyticsGuide: pop-up for push subscriptionsCase: Creating a pop-up with the "Wheel of Fortune" widgetBasic cases of placing a popup via the Tag Manager
        Tag Managerarrow
      • Configuring and installing Tag ManagerTrigger typesVariable typesLinking a pixel and the Tag manager
      Settingsarrow
    • Account settingsCustom linksVirtual sendersSending policiesAudit journalTags FAQ
        Users, groups and accessarrow
      • Password and login securityTwo-Factor Authentication (2FA)
        Connectionsarrow
      • Connection to Facebook Ads ManagerConnection to Google AdsConnecting to Yandex.Audience™Connection to 360dialogConnection to EdnaConnection to Devino TelecomConnection to SMSTrafficConnection to VK Ads™Connection to MTS OmniChannelCustom Authentication ConnectionOAuth2 connectionBasic Authentication connectionToken Authentication connectionConnection to RapportoMAX connectionConnection to Notify
      Attribute settings
      API requests: where to startarrow
    • Import or update a profileTrigger mailing launchEngage profile in scenario
      Changelogarrow
    • v2026.3.78v2026.2.77v2026.1.76v2025.4.75v2025.4.74v2025.3.73v2025.2.72v2025.1.71v2024.4.70v2024.3.69v2024.2.68.2v2024.1.68
    Documentation archiveEmail Marketer's Library
  • Settings
  • Users, groups and access
  • Password and login security

Password and login security

Altcraft Platform protects user accounts from unauthorized access: passwords must meet specific requirements, failed login attempts trigger temporary blocking, and users receive email notifications about failed login attempts.

Password requirements​

The account password must be 8 to 32 characters long and include numbers and special characters. The platform validates the password when it is set or changed and does not allow:

  • reusing a password that was previously set for the account;
  • using user data in the password;
  • setting a password that is too simple.

When requirements are not met, the platform reports the reason: "Password must contain numbers", "Password must contain special characters", "User data cannot be used in password", "The password you specified has already been used. Please enter a different password.", "Password must be different from the previous one!".

If the User must change password on first login option is enabled when the user is created, the user will set an individual password on the first login to the platform. Creating user accounts is described in the article Users and access separation.

Changing the password​

The password can be changed in the profile: My profile → Security. In the Password block, enter the current password, then enter the new password and confirm it.

If the current password is incorrect, the platform reports "Invalid current password!"; if the new password and its confirmation do not match, it reports "Confirmation password does not match your new password. Please try again.". A successful change is confirmed with the "Password updated successfully!" message.

Password recovery​

If the password is lost, use the "Forgot password?" link on the login page. An email with a recovery link will be sent to the user's contact email address, allowing the user to set a new password.

Login blocking after failed attempts​

To protect against password brute-forcing, the platform tracks failed login attempts by the IP address they come from. The attempt counter is shared for an IP address: failed login attempts under different logins from the same address are summed up.

When the failed attempt limit is exceeded (by default, 5 attempts within 60 seconds), further login attempts from this IP address are temporarily rejected, and the platform reports: "The limit of the number of authorization attempts has been exceeded!".

info

The block lasts for 60 seconds after the last failed attempt. Each new failed attempt resets the countdown: the block is prolonged for another 60 seconds. If no attempts are made within 60 seconds, login from the IP address becomes available again.

The attempt limit and the period are set in the platform configuration file and cannot be changed in the user interface. See the article Configuration file for details.

Failed login attempt notification​

When a login attempt fails, the platform sends the user an email "Failed login attempt" to the contact email address. The email contains the date of the attempt, the browser, and the IP address.

caution

If a notification arrives when no login attempt was made, the password should be changed and the support team should be contacted.

Login history​

Information about account logins is displayed in the Login history block (My profile → Security). The block shows successful and failed login attempts: login date, device, browser, location, and IP address. The location is determined by the IP address the login attempt came from.

Two-factor authentication​

Two-factor authentication provides additional account protection — it is described in the article Two-factor authentication (2FA).

Last updated on Aug 19, 2026
Previous
Users, groups and access
Next
Two-Factor Authentication (2FA)
  • Password requirements
  • Changing the password
  • Password recovery
  • Login blocking after failed attempts
  • Failed login attempt notification
  • Login history
  • Two-factor authentication
© 2015 - 2026 Altcraft, LLC. All rights reserved.