Account & security
Your Rankealo account owns domains, billing, and API keys. Treat keys like passwords — scoped, revocable, and never committed to git.
Account settings#
Manage profile and security under Settings (/settings) in the app. Sign in via email/password or your configured auth provider through Supabase Auth.
Password changes and session sign-out are standard. Enable MFA when your auth provider supports it for your organization.
Domains & access#
Each onboarded domain (onboarding record) isolates content, integrations, API keys, and billing. API keys cannot cross domains — an intentional guardrail for agencies.
API key hygiene#
- Create separate keys per agent or integration; revoke unused keys.
- Prefer read scope unless the tool truly needs publish or settings writes.
- Store keys in environment variables — never in client-side code or public repos.
- Rotate immediately if a key leaks; Rankealo only displays the full secret once at creation.
See REST API and MCP server.
CMS credentials#
Integration passwords and tokens are write-only in the UI after save. Rankealo encrypts stored CMS credentials server-side. Revoke Application Passwords or API keys on the CMS side when offboarding Rankealo.
Data & privacy#
Rankealo processes your site content, keywords, and analytics data to generate and measure articles. See the Privacy policy and Terms of service for retention, subprocessors, and contact details.
Questions: contact@rankealo.ai
Still stuck? Contact support
