Password & Login Security

Learn about Swipe Aras login sessions, password security, and account protection. Sessions last 24 hours with auto-refresh for 7 days of activity.

Swipe Aras uses secure, stateless JWT-based sessions. Here's what you need to know about login and password security.

Session Duration

Your login session is maintained through two tokens working together:

  • An access token keeps you logged in for 24 hours of active use

  • A refresh token automatically extends your session for up to 7 days of activity, so you don't have to log in every day if you use the dashboard regularly

    After 7 days without activity, both tokens expire and you'll be prompted to log in again. There is no "remember me" option that extends beyond this window.

MFA and SSO

Swipe Aras does not currently support Multi-Factor Authentication (MFA) or Single Sign-On (SSO). All accounts authenticate using email and password only.

If MFA or SSO support is important to your team, let your account manager know — feedback on missing security features helps prioritize the roadmap.

Changing Your Password

From within the app (when you're logged in):

  1. Go to your Profile Settings

  2. Select Change Password

  3. Enter your current password and your new password

  4. Save

Resetting a Forgotten Password

From the login screen (when you're locked out):

  1. Click Forgot password? on the login page

  2. Enter your email address

  3. Check your email for a reset link

  4. Click the link and set a new password

Password reset links expire after 1 hour and are single-use. If your link has expired, return to the login page and request a new one.

Password Security Standards

  • Passwords are hashed using bcrypt with industry-standard security settings

  • Swipe Aras staff will never ask for your password

  • If you believe your account has been compromised, change your password immediately and contact support

Account Security Notes

  • API keys are separate from your login — compromised API keys can be regenerated without changing your password. See API Key Permissions & Security.

Did this answer your question?
😞
😐
😁