A fast, secure path to your Uphold dashboard on web and mobile.
Sign in on the web
Follow these steps to log in safely from a desktop browser:
- Open your browser and type
https://www.uphold.cominto the address bar (avoid email links). - Select Sign in and enter the email you registered with.
- Provide your password and complete any CAPTCHA prompts if shown.
- When prompted, complete your second factor (SMS code, TOTP app, or security key).
- After authentication, confirm the login notification sent to your email to verify the activity.
Mobile app sign-in
The mobile workflow is streamlined for convenience and security:
- Install the official Uphold app from the App Store or Google Play.
- Open the app and enter your email and password or use the quick passcode if previously configured.
- Approve 2FA or use biometric unlock (Face ID / Touch ID) for subsequent, faster access.
Multi-Factor Authentication (MFA) — choose the best option
Protecting your account with an extra factor is essential. Here are the MFA options and recommendations:
Authenticator apps (recommended)
Use TOTP apps (Authy, Google Authenticator, Microsoft Authenticator). They are resilient, easy to use, and not tied to your phone number.
Hardware security keys (strongest)
YubiKey and other FIDO2-compliant keys provide phishing-resistant, device-based protection. Keep a backup key in a separate secure location.
Setting up MFA
- Go to your Uphold account > Security > Two-factor authentication.
- Select your method, scan the QR or register your key, and verify the generated code.
- Save backup codes in a secure offline location — they are the fallback if you lose access to your device.
Account recovery & lost access
Even cautious users can lose access. Uphold’s recovery process balances speed with safety to prevent unauthorized takeovers.
Forgot your password?
- Use the "Forgot password" link on the sign-in screen.
- Enter your registered email and follow the secure reset link sent by Uphold.
- Set a strong, unique password and re-enable MFA if needed.
Lost your 2FA device?
First, try your saved backup codes. If unavailable, open a support ticket via Uphold's official help center and follow the identity verification procedures. Expect identity checks — this prevents stealthy account takeovers.
Withdrawal protection & operational safety
Withdrawals are the highest-risk interactions. Use these controls to limit exposure:
- Withdrawal whitelist: restrict outgoing transfers to pre-approved addresses.
- Confirm addresses manually: copy-and-verify or use QR codes to avoid clipboard malware.
- Small test transfers: always send a small amount to a new address first.
- Review pending withdrawals: enable email alerts for each withdrawal and enable manual approvals where offered.
Troubleshooting — quick fixes
Invalid credentials
Check for Caps Lock, extra whitespace, and confirm you’re using the correct email. Try a password manager autofill if available.
2FA codes not accepted
- Ensure your device clock is synced to network time (TOTP relies on this).
- Use the most recent code shown by your authenticator app; codes typically rotate every 30 seconds.
- If using SMS, verify carrier delivery; consider switching to TOTP for reliability.
App or browser issues
- Clear cache or try an incognito/private browsing window.
- Update the app to the latest version from the official store.
- Disable third-party extensions that affect network requests or page rendering.
Privacy & regulatory notes
Uphold operates under regulatory frameworks that may require identity verification (KYC) for fiat services. Understand how your personal data is used and retained by reviewing official privacy policies when onboarding.
Minimize data exposure
- Only upload required documents for verification; redact optional sensitive fields when permitted.
- For on-chain privacy, avoid address reuse and consider using fresh receiving addresses for new counterparties.
Daily security checklist
- Use a unique password stored in a trusted password manager.
- Enable MFA (authenticator app or hardware key).
- Keep operating system and browser up to date.
- Verify URLs before signing in and avoid login links in emails unless you initiated them.
- Review account activity and revoke stale API keys or sessions.