How to Complete Security Initialization After Registering an OKX Account with Email?

 / 
OKX
 / 
2

Email registration is only the first step – your account is in an "unprotected" state by default. The core of security initialization is completing identity verification (KYC) to unlock trading permissions, and enabling two-factor authentication (2FA) and other security measures to lock down your account. Follow the three steps below in order. Only after completing them is your account truly "ready for use".

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

1. Step 1: Complete Identity Verification (KYC)

What to do: Submit your ID document and complete facial recognition to unlock trading, deposit, and withdrawal functions.

How to do it:

  1. On the app homepage, tap the profile icon in the top-left corner → tap your nickname/account at the top → [Identity Verification] → [Verify Now].

  2. Upload clear photos of the front and back of your ID (no glare, no obstructions).

  3. Follow the prompts to complete liveness detection (nod, blink, and other dynamic actions).

  4. Submit and wait for review. This usually takes within 5 minutes, and no longer than 24 hours at the latest.

When is it considered complete: The account status shows "Verified" or "Standard Identity Verification", and trading, deposit, and withdrawal functions are unlocked.

Accounts without completed KYC cannot perform any trading, deposits, or withdrawals. After email registration, you must complete this step for the account to be truly usable.

2. Step 2: Enable Two-Factor Authentication (2FA)

What to do: Bind an authenticator app (such as Google Authenticator) in the Security Center. This is the most critical step to protect your account.

How to do it:

  1. Open the OKX app, tap the profile icon in the top-left corner → [Security Settings] → [Security Center].

  2. Tap [Authenticator App] → select [Continue].

  3. Use the authenticator app on your phone (e.g., Google Authenticator, Authy) to scan the QR code on the page, or manually enter the key to bind.

  4. Enter the 6-digit dynamic code generated by the authenticator, tap [Enable Now] to complete binding.

  5. Important: After successful binding, the system will provide a set of backup recovery codes – write them down and store them safely. Do not save them on your phone. If you change or lose your phone, you can use them to recover access.

When is it considered complete: Your authenticator app generates a dynamic code for your OKX account that refreshes every 30 seconds.

SMS verification codes offer weaker protection than an authenticator app, so prioritize using an authenticator.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

3. Step 3: Set Up Anti-Phishing Code and Withdrawal Protection

What to do: Configure additional security measures to guard against phishing attacks and control the risk of fund outflows.

How to do it:

  1. Set an anti-phishing code: Go to [Security Center] → [Anti-Phishing Code] and set a unique string. Once set, every official email from OKX will display this code in the body – if it's missing, the email is a phishing attempt.

  2. Configure a withdrawal whitelist: Go to [Fund Security] → [Withdrawal Settings], turn on [Address Whitelist], and add your commonly used withdrawal addresses (addresses of your own external wallets). Future withdrawals can only be sent to these addresses.

When is it considered complete: The anti-phishing code is successfully set; the whitelist function is enabled and the list contains at least one trusted address.

After security initialization, the platform may enforce a 24-hour cooling-off period on sensitive operations like withdrawals – this is a normal security mechanism.

How to confirm you have completed the security initialization?

Go to [Security Center] and verify that "Identity Verification" shows "Verified", the "Authenticator App" is bound, and the "Anti-Phishing Code" is set – when all three are done, your account is basically secured. It is recommended to regularly check the list of login devices, remove any unknown devices, and make it a habit to change your password every 3–6 months.