> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mogalts.win/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Safety

> Keep your accounts and API key safe

## Your Microsoft Account is Safe

**Your own Microsoft account is never touched.** Logging in with an alt's token or cookie signs you in as *them*, not you. Your personal Microsoft session stays separate.

## Best Practices

<Warning>
  **Don't paste tokens into random websites.** Only use vetted mods — SchubiAuthV2, TokenLogin, and your client's native cookie import.
</Warning>

<Warning>
  **Keep your MOG API key private.** Anyone with it can drain your credits. Regenerate if leaked — Dashboard → API Key → Regenerate.
</Warning>

## What We Track

* **Replacements are logged.** Abusing the window (claiming false bans) is detectable and will result in account suspension.
* **API usage is rate-limited.** 200 requests per minute per key.

## MFA Accounts

Some accounts come with 2FA / Secret Key credentials. These require extra steps to log in.

<Card title="MFA Login Guide" icon="shield-halved" href="/mfa/overview">
  Step-by-step instructions for accounts with 2FA enabled
</Card>

## If Something Goes Wrong

1. **Cookie doesn't work** — Not a replacement. Test immediately after purchase.
2. **Token expired** — Normal. Use the cookie instead.
3. **API key compromised** — Regenerate immediately in Dashboard → API Key.
4. **Suspicious activity** — Open a `/ticket` in Discord.
