Account, Billing, and API Keys
Your profile and time zone, password and two-factor login, plans and payment, and connecting WordPress.
Everything about you rather than your links lives under the Account menu in the top-right corner: your profile, password, extra login security, your plan and payments, and keys for connecting other software.
Account: your profile and time zone
Open Account › Account. You can change:
- First name and Last name.
- Email — shown for reference and cannot be edited here. It also tells you whether your address is Verified or Not verified yet.
- Time zone — used whenever a date or time is displayed anywhere in the app.
Click Save profile when you are done.
Change Password
Open Account › Change Password, enter your new password twice — in New password and Confirm new password — and click Update password. Passwords must be at least 8 characters.
If you cannot sign in at all, use the Forgot password? link on the sign-in page instead.
MFA Settings: making your account much harder to break into
MFA (multi-factor authentication, sometimes called two-factor or 2FA) means a password alone is not enough to sign in. You also need a short code. If someone steals or guesses your password, they still cannot get in.
Open Account › MFA Settings, turn on Enable multi-factor authentication, and click Save. Then you have two ways to receive codes:
- Email codes
- Always available once MFA is on. A code is emailed to your account address when you sign in. Nothing to set up.
- Authenticator app
- Optional but faster and more reliable than email. Install an authenticator app on your phone, scan the QR code shown on the page, then type the code it displays into Authenticator code and click Confirm authenticator app. You can scan the same QR code on more than one device — they all show the same codes. If you cannot scan, type the Manual key into the app instead.
The page also offers Recovery codes. These are one-time codes that get you in if you lose your phone. They are shown only once, so save them somewhere safe — a password manager or a printed copy kept away from your computer.
Billing: plans, upgrades and cancelling
Open Account › Billing. Your current subscription status is shown at the top, and each plan card lists its price, billing interval, any trial period, and its limits:
- how many links it allows
- how many domains it allows
- whether custom domains are included, or the platform domain only
- how long click history is kept (in days; 0 means keep forever)
Your active plan is marked Current plan. To move to a different one, click Select plan, Upgrade, or Start Free on the card you want.
A direct sign-up link for one plan (it looks like /register?product=…) does not ask you to pick a plan again. After you create the account, checkout for that plan starts the same way as clicking Subscribe on its card. Free plans are applied immediately and you go to the dashboard.
After you pay, Stripe sends you back to a confirmation page. That page confirms the plan and offers Go to dashboard. The plan is active as soon as you land there, so you can use the app without choosing a product again. Open Billing later when you want to change plans.
Manage Billing takes you to the payment provider to update your card, see invoices, and download receipts. Use it for anything to do with payment details rather than plan choice.
Cancel subscription is a separate button and it is not immediate — you keep access until the end of the billing period you have already paid for, and you are not charged again after that.
Team (owners, admins, editors)
Open Account › Team to invite collaborators and review member access. Team invites are controlled by your product plan: only plans with Allow team invites enabled can send invites.
- Owner: full account access, including billing.
- Admin: can manage team members and account operations, but cannot cancel billing.
- Editor: can work with links, domains, analytics, and logs but cannot manage API keys, billing, or invites.
Team members use their own SCT login and can switch between their own account and shared owner accounts from the top-right account menu. Accounts without the team feature can still join another owner's team when invited.
API Keys: connecting other software
An API key is a long secret string that lets another program act on your account. Most people only ever need one, for connecting WordPress (SCT Connect) or the standalone SCT script on a non-WordPress PHP site. If nothing you use asked you for a key, you can ignore this page entirely.
Open Account › Integrations and click Create API Key:
- Name — a label so you remember what this key is for, such as
Main WordPress site. When you have several keys, this is the only way to tell them apart. - Key Type — choose Connect (WordPress or standalone script) for SCT Connect or the standalone PHP script, or MCP (AI/Automation) for AI tools and automation.
- Permissions — for MCP keys, tick only what the tool genuinely needs: Create links, Read links, Update links, Delete links. Leaving Delete links unticked means a mistake in that tool cannot wipe out your links. This is the single most useful safety habit on this page.
- Expiration — optional. Set a date if the key is for a temporary project or someone else's tool, and it stops working by itself when you forget about it.
The table lists your keys with their Prefix (the first few characters, so you can identify a key without exposing it), permissions, expiry, when it was Last Used, and whether it is Active or Revoked. Revoke switches a key off permanently — do that the moment a key is no longer needed or you think it may have been exposed.
Connecting a WordPress site (SCT Connect)
The SCT Connect plugin lets your WordPress site handle short-link redirects without changing your DNS settings, so your site keeps working exactly as it does now. Open Account › Integrations:
- Download the SCT Connect plugin, then install it on your WordPress site.
- In the plugin settings, click Connect to Simple Click Tracker.
- Authorize the connection from this account.
- If Connect should serve redirects, enable redirect handling in the plugin. Leave it off if the legacy WordPress SCT plugin should keep handling redirects while you transfer links and click history — staying connected does not require redirects to be on.
Each WordPress site is independent. You can install SCT Connect on several sites that all belong to the same SaaS account; turn redirect handling on only where Connect should intercept visitors. Enabling it on one site does not affect the others. Probes and redirects always use that site’s own hostname, so links for other domains in your account are never served from the wrong site.
Standalone SCT script (non-WordPress PHP sites)
If your site runs PHP but is not WordPress, download the standalone sct package from Integrations, upload it to your site’s web root, paste a Connect API key into config.php, and open /sct/install.php once. Full steps and when to choose this path: Using Your Own Domain.
The MCP Server URL card on the same page is for AI and automation tools, which send your key in an X-API-Key header. If that means nothing to you, you do not need it.
Keeping your account safe
- Turn on MFA, and store your recovery codes somewhere other than your computer.
- Give each connected tool its own key, so you can revoke one without breaking the others.
- Grant the fewest permissions that actually work.
- Never paste an API key into an email, a chat message, or a support ticket.
- Review the Last Used column occasionally and revoke keys nothing is using.