Your Microsoft Account is Safe
Your own Microsoft account is never touched. Logging in with an alt’s token or cookie signs you in as them, not you. Your personal Microsoft session stays separate.Best Practices
What We Track
- Replacements are logged. Abusing the window (claiming false bans) is detectable and will result in account suspension.
- API usage is rate-limited. 200 requests per minute per key.
MFA Accounts
Some accounts come with 2FA / Secret Key credentials. These require extra steps to log in.MFA Login Guide
Step-by-step instructions for accounts with 2FA enabled
If Something Goes Wrong
- Cookie doesn’t work — Not a replacement. Test immediately after purchase.
- Token expired — Normal. Use the cookie instead.
- API key compromised — Regenerate immediately in Dashboard → API Key.
- Suspicious activity — Open a
/ticketin Discord.
