The email verification code (and the authenticator app)
Before a sensitive action on agorapanel.com (showing your key, refunding, managing a subscription), the site checks it is you with a 6-digit code sent by email.
Updated on Oct 5, 2026, 1:36 p.m.
On this page
In short. Your license key gives access to your product: the site does not show it lightly. Before a sensitive action, it checks it is really you by sending a 6-digit code by email, to your confirmed address. Nothing to turn on: it is the default check.
When the code is asked #
- showing your license key, or downloading the
.envfile or the panel egg (they contain your key); - requesting a refund;
- renewing or managing a subscription, opening the Stripe billing portal;
- confirming or canceling a tier change (Basic ↔ Pro): confirming charges your card right away;
- choosing your reward for the 10th referral (one-time, final choice, see Referrals);
- turning on the authenticator app (see below);
- changing your account's address.
Receive and enter the code #
- Do the action (for example Show the key). The site tells you which address it will write to.
- Click Send me a code.
- Open the email and enter the code. It is valid for 10 minutes and works once. You can paste it as is, with its space ("123 456").
- You come back to the page and the site tells you ("Verification done: nothing has been done yet"). You still have to click the button of the action again, this time it goes through.
A new code cancels the previous one. You can ask for 3 per 15 minutes and 10 per 24 hours (per account). After 5 wrong tries, the code is cancelled: ask for a new one. At each mistake, the screen tells you how many tries are left ("3 attempts left before this code is cancelled").
If you opened two tabs and one of them has already done the verification, the other simply lets you continue: no code is used up.
Not working? #
| Message | What to do |
|---|---|
| "Your account has no confirmed email address" | Confirm it in My account → Emails: see Confirm my email address, then start again |
| "Your session has expired or is no longer valid" | No code would fix that: click Sign in again (Discord), then do the action again |
| Nothing in your inbox | Check spam, then Send a new code |
| "This code is no longer valid" | It expired, was already used or replaced: ask for a new one |
| "Incorrect code. N attempt(s) left…" | Check the code in the most recent email (a new code cancels the old one) |
| "Too many codes requested" / "Too many verification attempts" | Wait for the delay shown, then try again |
| "The email could not be sent" | Try again in a moment; if it keeps failing, open a ticket |
Going further: the authenticator app #
In My account → Security, you can turn on two-factor authentication with an app (Google Authenticator, Authy, 1Password, Bitwarden...): you scan the QR code, enter a first code, and write down the 8 recovery codes (shown only once, each usable once). Once on, the app's code is what is asked, and the email code stays available as a fallback ("Get a code by email instead"). The code comes from your phone, without going through your mailbox: it is safer.
Turning on the app first requires a verification. If your address is confirmed, the site first sends you an email code before showing the QR code, then brings you back to the setup: without that, someone who borrowed your session could enroll their own phone.
Too many wrong codes #
After 5 wrong app codes in a row, entry is blocked for 15 minutes. Each new series of 5 wrong codes lengthens the block: 15 minutes, then 1 hour, then 24 hours. Only an accepted code (app or recovery code) resets the counter. During a block, the screen says so ("…app codes blocked for N h. A recovery code still works."): a recovery code is still accepted, it is the owner's way out. If you have none left, open a ticket.
The two ways each have their own block: a block on the app does not grey out Send me a code (that is the fallback), and the limit on email codes sent does not block entering an app code. The screen counts the delays by itself: the button reopens when the block ends, without reloading the page.
The Agora team #
Agora team accounts are held to a stricter rule: the authenticator app is mandatory (the email code is not enough) and their session lasts only 12 hours from sign-in, instead of being extended at each use.
Was this article helpful?
Related articles
- Confirm my email addressYour confirmed address receives your key, your receipts and the verification codes: you confirm it by clicking a single-use link valid for 24 hours.
- Activate or change your license keyThe key is read in your customer space, set on the first start, and later replaced in Administration → Agora without touching the server.
- Request a refundSelf-service refund, approved automatically: 7 days for a month, 30 days for a year or a lifetime license; no prorating.
- Manage your subscription and its renewalTurn renewal off or back on, extend with a one-time payment, and what happens at the end date: the license stays active, then 14 days of grace.
- Open a support ticketSupport works through tickets, on Agora's Discord, on the site or by email: a short form, a reply from the team, and the transcript when it closes.