Getting Started

Account Security: OAuth, Sessions, and Best Practices

How Serpverse account security works with Google and Microsoft OAuth. Covers session management, provider locking, and protecting your sign-in accounts.

Last updated 10 min read

How Serpverse Account Security Works

Serpverse account security starts with a deliberate design choice: the platform does not store passwords. Every account authenticates through Google OAuth, Microsoft OAuth, or Email Magic Links, which means your security depends on the strength of your Google or Microsoft account (or email inbox) rather than a separate set of credentials.

This guide explains how authentication works, what happens with your sessions, how provider linking works, and what to do if something goes wrong.

Authentication Through OAuth

When you sign in to Serpverse, you are redirected to either Google or Microsoft to verify your identity. Serpverse never sees or stores your password. Instead, the OAuth provider confirms that you are who you claim to be and sends back a token that grants access to your Serpverse account.

What Serpverse receives from your OAuth provider:

  • Your email address
  • Your full name (kept private — visible only to you and admins; the other party in an order only ever sees your display name)
  • A unique provider ID (used to link your OAuth identity to your Serpverse account)

What signing in does not give Serpverse:

  • Your password
  • Your contacts, calendar, or other account data
  • Access to your email inbox or files

Connecting Google Search Console (Publishers)

Publishers can prove they own a listed website by connecting Google Search Console. This is separate from signing in, entirely optional, and never requested when you log in — you only see it if you pick that method to verify a listing.

What the connection can do: read the list of Search Console properties your Google account owns, so Serpverse can confirm your website is among them.

What it cannot do: change anything in Search Console, read your search performance data, or reach any other part of your Google account. The permission is read-only.

Three things worth knowing before you use it:

  • It can use a different Google account than the one you sign in with. Google will ask you to choose an account, which is expected — the account that owns a Search Console property often isn't the one you sign in to Serpverse with. Picking a different one doesn't create a second Serpverse account and doesn't change how you sign in.
  • Access isn't kept. Serpverse reads your property list once, at the moment you connect, and doesn't hold on to access afterwards.
  • You can revoke it safely. Serpverse will appear on Google's third-party access page(opens in new tab), possibly under whichever account you chose. Removing it is safe and doesn't un-verify any listing you've already verified.

If you'd rather not connect a Google account at all, the file-upload and DNS methods prove the same thing — see verifying domain ownership.

Sign-In Methods and Your Account

Serpverse supports three sign-in methods: Google OAuth, Microsoft OAuth, and Email Magic Links. Your account is tied to the first method you used when you signed up. The sign-in methods are not automatically linked together by a shared email address.

How this works in practice:

  • Whichever method you sign up with first becomes the way you sign in to that account
  • If you signed up with Google and later try to sign in with Microsoft (or a magic link) on the same email, Serpverse will not merge them — instead you'll see a message that the email is already associated with another sign-in method
  • To get back into your account, use the original method you signed up with (or the magic link for that email address)

Practical implications:

  • Pick one sign-in method and stick with it so you always land in the same account
  • This rule is about signing in only. Connecting Google Search Console to verify a website is a different thing entirely, and it's fine — expected, even — to use a different Google account for it
  • Using a different method on the same email won't open your existing account — it shows the "already associated with another sign-in method" message instead
  • Signing up with a genuinely different email address creates a separate account

See the sign-in troubleshooting guide if you encounter issues during sign-in.

Session Management

After successful authentication, Serpverse creates a session that keeps you signed in. Here is how sessions work.

Session Duration

Once you sign in, your session stays active for up to 30 days, so you don't have to sign in again every time you visit. After that, you'll be asked to sign in once more through your provider. The session is tied to the browser you signed in with, so signing in on a new browser or device starts a fresh session there.

What Your Session Tracks

While you're signed in, Serpverse remembers a few basics so it can show you the right experience:

DetailPurpose
Your accountKeeps you signed in to your own account
RoleBuyer or Publisher — determines which dashboard you see
Account statusActive, suspended, or banned
Display nameShown in the UI and order communications

Signing Out

You can sign out from any page using the account menu. Signing out clears your session in that browser, so you'll need to sign in again through your provider to get back in. Because the session lives in your browser, signing out on one browser does not sign you out on another — sign out on each device you've used if you're on a shared or public computer.

Signing out of Serpverse does not sign you out of Google or Microsoft. These are independent sessions.

What to Do If You Cannot Sign In

Most sign-in issues fall into predictable categories. Work through these in order:

1. Wrong Sign-In Method

The most common issue. If you see a role selection screen, a "complete your profile" prompt, or a message that your email is already associated with another sign-in method, you're signing in with a different method than the one your account was created with. Go back and sign in using your original method (or the magic link for that email).

Stale session cookies can prevent successful authentication. Clear cookies specifically for serpverse.io in your browser settings, then try again.

3. Ad Blocker Interference

Privacy extensions and ad blockers can block the OAuth redirect flow. Temporarily disable them or add serpverse.io, accounts.google.com, and login.microsoftonline.com to your allowlist.

4. Corporate Network Restrictions

If you are on a corporate network, your IT department may block OAuth redirect URLs. Try signing in from a personal device or mobile data connection.

Securing Your OAuth Account

Because your Serpverse account security is only as strong as your underlying OAuth account, protecting that Google or Microsoft account is critical. A compromised OAuth account means a compromised Serpverse account.

Enable Two-Factor Authentication (2FA)

This is the single most effective security measure you can take.

Google:

  1. Go to Google Account Security(opens in new tab)
  2. Under "How you sign in to Google," enable 2-Step Verification
  3. Choose your verification method: authenticator app (recommended), security key, or phone prompts

Microsoft:

  1. Go to Microsoft Account Security(opens in new tab)
  2. Under "Additional security options," enable two-step verification
  3. Set up the Microsoft Authenticator app or an alternative method

Use a Strong, Unique Password on Your OAuth Account

Your Google or Microsoft password should be:

  • At least 12 characters long
  • Unique (not reused on any other service)
  • Stored in a password manager rather than memorized or written down

Review Connected Applications

Periodically review which applications have access to your OAuth account:

Revoke access for any applications you no longer use. While Serpverse needs to remain authorized for sign-in, removing unused applications reduces your attack surface.

If you've verified a website through Search Console, you may also find Serpverse listed with Search Console access — possibly under a different Google account than the one you sign in with. That entry is safe to revoke; it doesn't affect your sign-in or un-verify any listing.

Monitor Sign-In Activity

Both Google and Microsoft provide sign-in activity logs. Check these periodically for unrecognized devices or locations:

If you see a sign-in you do not recognize, change your password immediately and review your Serpverse account for any unauthorized activity.

Account Roles and Permissions

During initial setup, you select a role — Buyer or Publisher — along with a display name. This role determines which features and dashboard sections you can access.

FeatureBuyerPublisher
Browse marketplaceYesNo
Place ordersYesNo
Deposit fundsYesNo
List websitesNoYes
Accept ordersNoYes
Withdraw earningsNoYes
Order messagingYesYes
File disputesYesNo

Your initial role is not permanent. You can switch between Buyer and Publisher at any time using the role switcher in your dashboard sidebar. Review the getting started guide for details on the initial role selection process.

Account Suspension and Access

Serpverse may suspend accounts for policy violations. A suspended account keeps full read access — you can still sign in, browse, and read your orders and messages — but actions like placing or accepting orders, withdrawing funds, and sending new messages are blocked. A suspension doesn't cancel your existing orders or move your funds. If your account is suspended:

  • You will receive an email explaining the reason and any steps required to resolve it
  • Your data and order history remain intact during suspension
  • Follow the instructions in the suspension notice to request reinstatement
  • See the publisher rules for enforcement details

Security Checklist

Use this checklist to audit your account security:

  • 2FA enabled on your Google or Microsoft account
  • Strong, unique password on your OAuth account
  • Unused third-party app permissions revoked
  • Sign-in activity reviewed for unrecognized access
  • Correct OAuth provider remembered for Serpverse sign-in
  • Ad blockers configured to allow Serpverse and OAuth domains

Still have questions?

Can't find what you're looking for? Our support team is here to help.

Account Security: OAuth, Sessions, and Best Practices | Serpverse