Account Security: OAuth, Sessions, and Best Practices
How Serpverse account security works with Google and Microsoft OAuth. Covers session management, provider locking, and protecting your sign-in accounts.
Account Security
How Serpverse Account Security Works
Serpverse account security starts with a deliberate design choice: the platform does not store passwords. Every account authenticates through Google OAuth, Microsoft OAuth, or Email Magic Links, which means your security depends on the strength of your Google or Microsoft account (or email inbox) rather than a separate set of credentials.
This guide explains how authentication works, what happens with your sessions, how provider linking works, and what to do if something goes wrong.
Authentication Through OAuth
When you sign in to Serpverse, you are redirected to either Google or Microsoft to verify your identity. Serpverse never sees or stores your password. Instead, the OAuth provider confirms that you are who you claim to be and sends back a token that grants access to your Serpverse account.
What Serpverse receives from your OAuth provider:
- Your email address
- Your full name (kept private — visible only to you and admins; the other party in an order only ever sees your display name)
- A unique provider ID (used to link your OAuth identity to your Serpverse account)
What signing in does not give Serpverse:
- Your password
- Your contacts, calendar, or other account data
- Access to your email inbox or files
Connecting Google Search Console (Publishers)
Publishers can prove they own a listed website by connecting Google Search Console. This is separate from signing in, entirely optional, and never requested when you log in — you only see it if you pick that method to verify a listing.
What the connection can do: read the list of Search Console properties your Google account owns, so Serpverse can confirm your website is among them.
What it cannot do: change anything in Search Console, read your search performance data, or reach any other part of your Google account. The permission is read-only.
Three things worth knowing before you use it:
- It can use a different Google account than the one you sign in with. Google will ask you to choose an account, which is expected — the account that owns a Search Console property often isn't the one you sign in to Serpverse with. Picking a different one doesn't create a second Serpverse account and doesn't change how you sign in.
- Access isn't kept. Serpverse reads your property list once, at the moment you connect, and doesn't hold on to access afterwards.
- You can revoke it safely. Serpverse will appear on Google's third-party access page(opens in new tab), possibly under whichever account you chose. Removing it is safe and doesn't un-verify any listing you've already verified.
If you'd rather not connect a Google account at all, the file-upload and DNS methods prove the same thing — see verifying domain ownership.
Sign-In Methods and Your Account
Serpverse supports three sign-in methods: Google OAuth, Microsoft OAuth, and Email Magic Links. Your account is tied to the first method you used when you signed up. The sign-in methods are not automatically linked together by a shared email address.
How this works in practice:
- Whichever method you sign up with first becomes the way you sign in to that account
- If you signed up with Google and later try to sign in with Microsoft (or a magic link) on the same email, Serpverse will not merge them — instead you'll see a message that the email is already associated with another sign-in method
- To get back into your account, use the original method you signed up with (or the magic link for that email address)
Practical implications:
- Pick one sign-in method and stick with it so you always land in the same account
- This rule is about signing in only. Connecting Google Search Console to verify a website is a different thing entirely, and it's fine — expected, even — to use a different Google account for it
- Using a different method on the same email won't open your existing account — it shows the "already associated with another sign-in method" message instead
- Signing up with a genuinely different email address creates a separate account
See the sign-in troubleshooting guide if you encounter issues during sign-in.
Session Management
After successful authentication, Serpverse creates a session that keeps you signed in. Here is how sessions work.
Session Duration
Once you sign in, your session stays active for up to 30 days, so you don't have to sign in again every time you visit. After that, you'll be asked to sign in once more through your provider. The session is tied to the browser you signed in with, so signing in on a new browser or device starts a fresh session there.
What Your Session Tracks
While you're signed in, Serpverse remembers a few basics so it can show you the right experience:
| Detail | Purpose |
|---|---|
| Your account | Keeps you signed in to your own account |
| Role | Buyer or Publisher — determines which dashboard you see |
| Account status | Active, suspended, or banned |
| Display name | Shown in the UI and order communications |
Signing Out
You can sign out from any page using the account menu. Signing out clears your session in that browser, so you'll need to sign in again through your provider to get back in. Because the session lives in your browser, signing out on one browser does not sign you out on another — sign out on each device you've used if you're on a shared or public computer.
Signing out of Serpverse does not sign you out of Google or Microsoft. These are independent sessions.
What to Do If You Cannot Sign In
Most sign-in issues fall into predictable categories. Work through these in order:
1. Wrong Sign-In Method
The most common issue. If you see a role selection screen, a "complete your profile" prompt, or a message that your email is already associated with another sign-in method, you're signing in with a different method than the one your account was created with. Go back and sign in using your original method (or the magic link for that email).
2. Browser Cache or Cookie Issues
Stale session cookies can prevent successful authentication. Clear cookies specifically for serpverse.io in your browser settings, then try again.
3. Ad Blocker Interference
Privacy extensions and ad blockers can block the OAuth redirect flow. Temporarily disable them or add serpverse.io, accounts.google.com, and login.microsoftonline.com to your allowlist.
4. Corporate Network Restrictions
If you are on a corporate network, your IT department may block OAuth redirect URLs. Try signing in from a personal device or mobile data connection.
Securing Your OAuth Account
Because your Serpverse account security is only as strong as your underlying OAuth account, protecting that Google or Microsoft account is critical. A compromised OAuth account means a compromised Serpverse account.
Enable Two-Factor Authentication (2FA)
This is the single most effective security measure you can take.
Google:
- Go to Google Account Security(opens in new tab)
- Under "How you sign in to Google," enable 2-Step Verification
- Choose your verification method: authenticator app (recommended), security key, or phone prompts
Microsoft:
- Go to Microsoft Account Security(opens in new tab)
- Under "Additional security options," enable two-step verification
- Set up the Microsoft Authenticator app or an alternative method
Use a Strong, Unique Password on Your OAuth Account
Your Google or Microsoft password should be:
- At least 12 characters long
- Unique (not reused on any other service)
- Stored in a password manager rather than memorized or written down
Review Connected Applications
Periodically review which applications have access to your OAuth account:
- Google: Third-party apps with account access(opens in new tab)
- Microsoft: Apps and services(opens in new tab)
Revoke access for any applications you no longer use. While Serpverse needs to remain authorized for sign-in, removing unused applications reduces your attack surface.
If you've verified a website through Search Console, you may also find Serpverse listed with Search Console access — possibly under a different Google account than the one you sign in with. That entry is safe to revoke; it doesn't affect your sign-in or un-verify any listing.
Monitor Sign-In Activity
Both Google and Microsoft provide sign-in activity logs. Check these periodically for unrecognized devices or locations:
- Google: Recent security activity(opens in new tab)
- Microsoft: Recent activity(opens in new tab)
If you see a sign-in you do not recognize, change your password immediately and review your Serpverse account for any unauthorized activity.
Account Roles and Permissions
During initial setup, you select a role — Buyer or Publisher — along with a display name. This role determines which features and dashboard sections you can access.
| Feature | Buyer | Publisher |
|---|---|---|
| Browse marketplace | Yes | No |
| Place orders | Yes | No |
| Deposit funds | Yes | No |
| List websites | No | Yes |
| Accept orders | No | Yes |
| Withdraw earnings | No | Yes |
| Order messaging | Yes | Yes |
| File disputes | Yes | No |
Your initial role is not permanent. You can switch between Buyer and Publisher at any time using the role switcher in your dashboard sidebar. Review the getting started guide for details on the initial role selection process.
Account Suspension and Access
Serpverse may suspend accounts for policy violations. A suspended account keeps full read access — you can still sign in, browse, and read your orders and messages — but actions like placing or accepting orders, withdrawing funds, and sending new messages are blocked. A suspension doesn't cancel your existing orders or move your funds. If your account is suspended:
- You will receive an email explaining the reason and any steps required to resolve it
- Your data and order history remain intact during suspension
- Follow the instructions in the suspension notice to request reinstatement
- See the publisher rules for enforcement details
Security Checklist
Use this checklist to audit your account security:
- 2FA enabled on your Google or Microsoft account
- Strong, unique password on your OAuth account
- Unused third-party app permissions revoked
- Sign-in activity reviewed for unrecognized access
- Correct OAuth provider remembered for Serpverse sign-in
- Ad blockers configured to allow Serpverse and OAuth domains