The security verification screen
The identity check that appears before you enter Connection settings. Why it is asked, which methods are offered, and what to do if you have none.
Last updated: September 30, 2026
The identity check that appears before you enter Connection settings. Why it is asked, which methods are offered, and what to do if you have none.
Last updated: September 30, 2026
When you try to open Connection settings, the panel sometimes puts a screen in the way and asks you to verify your identity. Having already signed in with your password doesn't change that. This article explains why the screen appears, what it will ask for, and what to do if you get stuck.
Connection settings is the most sensitive page in the panel. It holds the account's access token, its webhook status and, on WhatsApp, its approved templates. The access token is the secret that lets the panel send messages on Meta's behalf: anyone who gets hold of it can write to your customers as you.
That is why the panel asks you to verify. The screen says as much itself: "Connection settings contain the account's access token; verify your identity to continue."
Verification is per session: once you verify, you can come and go from the Connection screen freely for the rest of that session. It is not asked on every click.
💡 If you never see this screen, don't worry: whether verification is required is a platform-wide setting that can be turned on or off. Where it is off, the Connection screen opens directly.
It comes up in three situations:
There is one thing it does not do: clicking Settings in the left menu doesn't drop you onto this screen. Because Connection is the first item in the menu, owners and admins would hit the verification screen on every single "Settings" click; the panel avoids that and, if you haven't verified, skips Connection and opens the next visible screen (usually General). When you go to Connection deliberately, verification is asked as normal.
The screen shows the methods enabled on your user account. If both are enabled you see both, and you choose.
If you have a passkey registered, a button appears. Tap it and your device takes over: you confirm with Face ID, your fingerprint or your device lock. No code to type.
This is the fastest route. For passkey setup see the Passkeys guide.
If two-step verification is enabled you see a single field called Verification code. Its hint: "The 6-digit code from your authenticator app (or a backup code)."
The field accepts two things:
abcde-12345).You don't have to say which you typed; the panel tells from the format. If you can't reach your phone, use one of your backup codes.
Fill it in and press Verify and continue. On success the panel takes you to the screen you were heading for.
If neither two-step verification nor a passkey is enabled on your user account, verification cannot happen. The screen says so plainly: "To open this screen you need a security method enabled on your user account: two-step verification or a passkey." A Go to security settings button sits underneath.
What to do:
If you don't have a preference, a passkey is more practical (no code to type), but two-step verification works on every device. Enabling both is the most comfortable: use the code when your phone isn't with you and the passkey when it is.
⚠️ The methods offered on this screen only verify you; they don't set anything up. To add a new method you must go to the Security screen.
On success the panel returns you to the address you were heading for before the check. That address is validated: you can only return to settings of the same account. If no address was given, the account's Connection page opens (Instagram connection for an Instagram account, WhatsApp for a WhatsApp one).
Asking on every click wouldn't add security, it would only slow you down: within one session you are already known to be the same person. The panel therefore treats verification as a property of the session.
The practical consequence: verify once in the morning and you can come and go from the Connection screen all day. But when you sign out, when your session times out, or when you sign in from another device, verification is asked again — because that is a new session.
Verification only opens channel settings. Moving an account, deleting an account, deleting a portfolio and deleting your user account each ask for their own confirmation; having verified in this session does not exempt you there. Those three carry irreversible consequences, so they ask every time.
A shop owner signs in one morning and sees a "This account's connection has dropped" banner on the account's home screen. They press the banner's Reconnect button and the security verification screen appears.
Because their phone is on the desk, they press Verify with passkey, touch their computer's fingerprint reader, and land straight on the Connection screen, where they renew the Instagram connection.
In the afternoon they open the Connection screen again to look at their templates; no verification is asked this time, because it is the same session. When they sign in from their phone at home that evening, the same screen has to be verified again.
Typing your panel password into the verification field. The field expects a 6-digit app code or a backup code; your password won't work.
Not saving your backup codes. The backup codes shown when you enable two-step verification are never shown again. If you lose your phone they are your only route.
Typing the code with a space. The app shows it as two groups of three (123 456), but the field takes it without the space.
Assuming verification is asked on every page. It is asked once per session.
Forcing the connection screen without enabling a method. Typing the address by hand doesn't help either; the gate is on the server.
For setting up a method see the Two-step verification and Passkeys guides. For the page this screen protects see The Instagram connection screen, and for what a token is see What is an access token.
Was this article helpful?