Skip to content

Account and security

Sign in and manage account access

Use password, OTP, or Google sign-in safely and manage store administrator access without sharing credentials.

Last updated
August 4, 2026
Audience
Store owners and administrators

What you’ll accomplish

  • Choose the correct sign-in method.
  • Recover a password safely.
  • Understand store selection and access-denied messages.
  • Invite or remove administrators without sharing the owner password.

Sign in

  1. 1

    Open the Vacto sign-in page.

    Use the same email attached to the seller account.

    Sign in
  2. 2

    Choose password, OTP, or Google when offered.

    Google sign-in works only for the linked/recognized account. An OTP is temporary and must not be shared.

  3. 3

    Complete verification and choose the store.

    Select store shows stores and requests available to this account. Access to one store does not grant access to another.

  4. 4

    If the session expired, sign in again.

    Vacto can revoke old or other sessions after password/security changes.

Reset or change the password

Use Forgot password from the sign-in page when you cannot use the current password. Complete the email/OTP verification in the same browser flow, then choose a new unique password. If already signed in, use Account settings to change the password and review other sessions where supported.

Store administrators

  1. 1

    Open administrator management for the selected store.

    Only a role with the required permission can add or remove administrators.

  2. 2

    Invite the person's own account/email.

    Do not give them the owner login.

  3. 3

    Assign only the permissions needed.

    Product, order, settings, billing, and administrator actions can have different access requirements.

  4. 4

    Remove access when the role ends.

    Then review active sessions and change shared business credentials outside Vacto where necessary.

If the result is not what you expected

  • If an OTP does not arrive, check the email address and spam folder, wait briefly, then request one new code rather than many.
  • If the store is missing, confirm the account email and ask the owner to verify the administrator membership.
  • If Access denied appears, the account is signed in but lacks the required store permission; ask the owner to review the role.

Was this article helpful?