Password recovery respects two-factor verification
Saving a password with a recovery code preserves two-factor verification, and connected checkouts can display the exact version of venue terms.
After saving a password with a recovery code, clients with two-factor authentication sign in with the new password to complete verification. If the verification service is temporarily unavailable, the password remains saved and clients return to sign-in without receiving an unverified recovery session. Connected checkouts can now display sanitized content from the exact version of the venue terms they ask clients to accept. This does not change the terms or their acceptance rules. Connected-site rollout and mobile device verification remain separate from this platform change.
Clearer messages when sign-in is temporarily unavailable
Password sign-in now explains temporary service failures and excessive attempts, and avoids starting account recovery during those failures.