Rankealo

Account & security

Your Rankealo account owns domains, billing, and API keys. Treat keys like passwords — scoped, revocable, and never committed to git.

Account settings#

Manage profile and security under Settings (/settings) in the app. Sign in via email/password or your configured auth provider through Supabase Auth.

Password changes and session sign-out are standard. Enable MFA when your auth provider supports it for your organization.

Domains & access#

Each onboarded domain (onboarding record) isolates content, integrations, API keys, and billing. API keys cannot cross domains — an intentional guardrail for agencies.

API key hygiene#

  • Create separate keys per agent or integration; revoke unused keys.
  • Prefer read scope unless the tool truly needs publish or settings writes.
  • Store keys in environment variables — never in client-side code or public repos.
  • Rotate immediately if a key leaks; Rankealo only displays the full secret once at creation.

See REST API and MCP server.

CMS credentials#

Integration passwords and tokens are write-only in the UI after save. Rankealo encrypts stored CMS credentials server-side. Revoke Application Passwords or API keys on the CMS side when offboarding Rankealo.

Data & privacy#

Rankealo processes your site content, keywords, and analytics data to generate and measure articles. See the Privacy policy and Terms of service for retention, subprocessors, and contact details.

Questions: contact@rankealo.ai

Still stuck? Contact support

Reading is step one. Measuring your AI visibility is step two.

Rankealo tracks how often your brand is mentioned and cited across the major AI engines, then helps you publish the pages that close the gaps.