CFDs are complex instruments and come with a high risk of losing money rapidly due to leverage. Trade only with money you can afford to lose.
Open Exness Account →

Exness Login — and What Still Asks After It

Signing in settles how the session started. It does not settle what comes next: moving money or restoring access is validated on its own, by the security type registered on the account rather than by the password just typed.

Open Exness Account →

100+ instruments  ·  Founded 2008

Being signed in is not the same as being confirmed. Inside a live session the actions that move money or restore access are validated separately: the request goes to the security type registered on the account, two-step verification issues a time-sensitive code, and the action proceeds only while that code is alive. What the step records is reach at that minute, not the password that opened the session — which is why it appears even when the sign-in itself went perfectly.

How a second step runs inside an open session

  1. Start the action from inside the session — a withdrawal from the Accounts tab, a password recovery from the sign-in screen.
  2. Fill in what the action needs and read the summary shown before it is submitted.
  3. Wait for the validation request, which goes to the security type registered on the account — an authenticator app, or a code sent to the registered email or phone.
  4. Answer it while the code is still alive: two-step verification issues a time-sensitive code, and an expired one is refused inside a perfectly healthy session.
  5. Confirm the action. The check belongs to the action, so the session carries on as it was.

Why the second step is not the password again

A password answers one question, once, at the moment the session opens: was the account entered with the right credentials. A validation attached to an action answers a different one — is the security type registered on the account within reach at the minute this particular action is made.

The two questions cannot stand in for each other, which is why the request appears when nothing about the sign-in has gone wrong. Two-step verification issues a time-sensitive code, so what the second step records is not knowledge but reach — and reach at that minute, not at the start of the session.

Open Exness Account →

Two different questions, two different answers

A session records how it began. It carries the fact that the right email and password were entered and it keeps carrying it for as long as it stays open, without learning anything new. That is enough for reading balances, opening charts and placing orders, because none of those change what the account is or where its money can go.

An action that moves money asks something the session cannot answer: is this being authorised now. The validation request is what answers it. It goes out to the security type registered on the account, and until it comes back the action is not carried out, while the session meanwhile stays exactly as it was.

So nothing has gone wrong when the request appears. It is not a doubt about the sign-in and it is not a repeat of it; it is a separate question, asked once per action instead of once per session.

Why the code has a clock on it

Two-step verification issues a time-sensitive code, and the short life of that code is the point of the check rather than an inconvenience attached to it. A code that stayed valid indefinitely would be a second password — something learned once and reusable forever — and the entire reason for the second step is that it is not that.

The practical consequence is that a validation left unanswered simply lapses. The code stops being accepted, the action is not carried out, and the request has to be made again from inside the same session. Nothing about the account changes in the meantime.

Which actions carry a validation and which do not

The line is drawn around money and access, not around effort. Opening or closing a position, moving between the accounts already held, changing a chart, reading the history of past orders — none of these are validated separately, because none of them take anything out of the account or hand it to anybody.

A withdrawal is validated: the amount and destination are reviewed, then the action is validated by the account security type before it is submitted. Restoring a password is validated too — a recovery started from the sign-in screen is checked against the security type before a new password is accepted. Between those points the session runs untouched, which is exactly what makes the occasional interruption noticeable.

Where the second step attaches

Action inside a live sessionValidated on its ownWhat that check answers
Opening or closing a position on MT4, MT5 or the TerminalNoNothing — the session already carries it
Reading account history and past ordersNoNothing
Moving between accounts already heldNoNothing
Requesting a withdrawalYesThat the registered security type is within reach right now
Restoring the password from the sign-in screenYesThat the recovery is answered by the security type on the account

Two-step verification issues a time-sensitive code; a validation that is not answered while the code is alive has to be requested again, and the action is not carried out.

Frequently asked questions

I am already signed in — why is another confirmation asked for?
Because the session and the action answer different questions. The session records that the sign-in was correct; the validation records that the security type registered on the account is within reach at the minute the action is made.
Which actions inside a live session are validated on their own?
The ones that move money or restore access. A withdrawal is reviewed and then validated by the account security type before it is submitted, and a password recovery is validated the same way. Opening and closing positions is not.
What does the second step actually check?
Reach, not knowledge. Two-step verification issues a time-sensitive code, so answering it shows that the security type registered on the account — an authenticator app, or a code sent to the registered email or phone — is available at that minute.
Why does the code stop working after a short time?
The short life of the code is the point of the check. An expired code is refused inside a perfectly healthy session, and the validation simply has to be requested again.
Does confirming an action change or end the session?
No. The check belongs to the action rather than to the sign-in, so once the action goes through the session continues exactly as it was.
Is the second step just the password again?
No. The password was answered once, when the session opened, and answering it a second time would say nothing new. The validation asks something a password cannot: that the registered security type can be reached now.
What happens if the validation is never answered?
The action is not carried out. The code lapses, the request has to be started again from inside the same session, and nothing else about the account changes.

Reviews

What traders report about the checks that come after signing in:

★★★☆☆
Two step verification code. I have been trying to withdraw some amount of money but anytime the app says a two step verification has been sent I do not receive it
— tchikata1262022-07-29
★☆☆☆☆
Withdrawal. Withdrawing is now a big time problem, they don’t send codes, i have to keep trying and trying. The “choose another method” option still sucks, please this should be fixed
— Gst105.12025-10-01
★★★★★
Super secure. Verifiable and reliable
— scottomoruyi2025-02-26

Related Exness pages