Mobile from sohib in your Account Ready.

sohib Two-Factor Authentication Live Casino App - Blackjack & Roulette

Account security on sohib begins with a strong password and extends to two-factor authentication (2FA), a second verification layer that prevents unauthorized access even if someone obtains your login credentials. We offer 2FA through authenticator apps and SMS codes, letting you choose the method that fits your workflow. Enabling 2FA takes under two minutes and protects your balance, withdrawal settings, and game history from compromise.

Open an account
sohib featured game showcase

Two-Factor Authentication

Live and
Category
Live Table / Card
RTP
medium

Two-factor authentication works by requiring a second proof of identity beyond your password. After you enter your username and password on sohib, our system prompts you for a time-based code from an authenticator app or a one-time SMS code sent to your registered phone number. Only after you provide this code does the login complete. This means that even if a third party knows your password, they cannot access your account without also controlling your phone or authenticator device.

Why Two-Factor Authentication Matters on sohib

Our platform holds your account balance, payment history, and personal information. A compromised account could lead to unauthorized withdrawals, fraudulent transactions, or identity theft. Two-factor authentication is the single most effective defense against account takeover because it requires physical possession of a device—your phone or a hardware token—that an attacker cannot easily replicate remotely.

We've seen account compromises occur when players reuse passwords across multiple websites. If one website is breached, attackers try the same username and password on other platforms, including sohib. With 2FA enabled, even a leaked password does not grant access. The attacker would need your phone or authenticator app, which they do not have.

Players across Jakarta, Surabaya, Bandung, Medan, and Semarang who manage significant balances or plan to withdraw regularly should treat 2FA as mandatory, not optional. We do not force 2FA on all accounts, but we strongly recommend it before your first deposit.

sohib account security settings showing two-factor authentication toggle
2FA toggle in account security settings
Authenticator app displaying six-digit code for sohib login
Authenticator app generates time-based codes
SMS verification code received on mobile phone for sohib login
SMS codes arrive instantly to your registered number
Security note: Two-factor authentication on sohib protects your account login. It does not protect your payment methods (DANA, e-wallet, mobile banking, local payment) directly—you should enable 2FA on those apps separately.

Setting Up Two-Factor Authentication

To enable 2FA on sohib, log into your account and navigate to Settings > Security > Two-Factor Authentication. You'll see two options: authenticator app or SMS. We recommend the authenticator app method because it does not depend on SMS delivery, which can be delayed or intercepted in rare cases.

Authenticator App Method

Download an authenticator app such as Google Authenticator, Microsoft Authenticator, or Authy on your phone. These apps are free and available on iOS and Android. Once installed, return to the sohib 2FA setup page and select "Authenticator App." Our system displays a QR code and a backup key (a long string of characters). Scan the QR code with your authenticator app, or manually enter the backup key if scanning fails.

Your authenticator app now displays a six-digit code that changes every 30 seconds. Enter the current code into the sohib setup form to confirm the app is synchronized with our servers. Once confirmed, 2FA is active. Every future login will require you to enter the current six-digit code from your authenticator app after entering your password.

Save your backup key in a secure location. If you lose your phone, you'll need this key to regain access to your account. Write it down and store it in a safe place—not on your computer or in an email account that could be compromised.

sohib 2FA setup screen showing QR code and backup key for authenticator app

Authenticator apps are more secure than SMS because they do not rely on cellular networks or SIM card vulnerabilities. We recommend this method for all sohib players.

sohib Security Team

SMS Method

If you prefer SMS, select "SMS" during 2FA setup. Enter your phone number and confirm. sohib will send a test code to verify the number is correct. Once verified, 2FA is active. Every login will prompt you to enter a six-digit code sent via SMS to your registered number. Codes expire after subject to verification, so enter them promptly.

SMS 2FA is convenient but slightly less secure than authenticator apps because SMS can be intercepted or redirected through SIM swapping attacks. However, it remains a strong defense for most players. If you use SMS, ensure your phone number is not publicly listed and that your mobile carrier account has a strong PIN or password.

Recovery Codes

When you enable 2FA, sohib generates recovery codes—a set of single-use backup codes you can use to log in if you lose access to your authenticator app or phone. Download or print these codes and store them securely. Each code can be used once. If you use all recovery codes, contact our support team to regain access to your account.

Setup Time
Under subject to verification
Methods
App or SMS
Code Duration
30 seconds (app)
Recovery
Backup codes

Tips and Account Recovery

Once 2FA is enabled, every login requires the second factor. This adds a few seconds to your login process but provides substantial security. If you're logging in from a new device or location, sohib may ask additional verification questions as part of our fraud-prevention system. This is normal and protects your account.

What to Do If You Lose Your Phone

If your phone is lost, stolen, or damaged, you can still access your sohib account using recovery codes. During login, when prompted for your 2FA code, select "Use a recovery code" and enter one of the codes you saved during setup. Each recovery code works once. After you regain access, you can disable 2FA, set it up again with a new device, or generate new recovery codes.

If you've lost both your phone and your recovery codes, contact our support team immediately. We'll verify your identity using your account details, KYC documents, and recent transaction history. Once verified, we can temporarily disable 2FA so you can log in and reset your security settings. This process may take one to two business days.

Protecting Your Authenticator App

Your authenticator app is as sensitive as your password. Do not share screenshots of the codes or the QR code with anyone. Do not install authenticator apps on shared devices. If you upgrade your phone, transfer your authenticator app to the new device before discarding the old one. Most authenticator apps allow you to export or back up your codes so you can restore them on a new device.

Two-factor authentication on sohib is your strongest defense against account compromise. Enable it before your first deposit, especially if you plan to withdraw via DANA, e-wallet, mobile banking, or local payment.

sohib Account Security

2FA and Withdrawal Requests

When you request a withdrawal on sohib, our system may ask for additional verification—including your 2FA code—to confirm the request is legitimate. This extra step prevents unauthorized withdrawals even if someone gains temporary access to your account. Always verify withdrawal requests carefully before confirming them.

Disabling or Changing 2FA

You can disable 2FA at any time from your account security settings. However, we recommend keeping it enabled. If you want to switch from SMS to an authenticator app (or vice versa), disable the current method and set up the new one. Your account will require 2FA during the transition, so have your current code ready.

Two-factor authentication is one layer of a comprehensive security strategy on sohib. Combine it with a strong, unique password; regular account monitoring; and caution when clicking links in emails or messages claiming to be from sohib. Our support team will never ask for your password or 2FA codes. If you receive such a request, it is a phishing attempt—do not respond.

Players across Indonesia who use sohib for live blackjack, roulette, baccarat, or football betting on Liga 1 and Piala AFF should treat account security as seriously as they treat their gaming strategy. Enable 2FA today, save your recovery codes, and enjoy your gaming sessions with confidence that your account and balance are protected. Our services are available only where local law permits; users are responsible for verifying that access and use comply with their own jurisdiction's regulations.

Security, Fairness, and Player Protections on sohib

Platform security layers

sohib employs multiple security layers to protect your account and personal data. All communication between your device and our servers is encrypted using SSL (Secure Socket Layer) technology, which prevents third parties from intercepting your login credentials, payment information, or game history. Your password is hashed using industry-standard algorithms, meaning we do not store your actual password—only a cryptographic representation that cannot be reversed.

Two-factor authentication adds a second verification layer beyond your password. Even if an attacker obtains your password through phishing or a data breach elsewhere, they cannot access your sohib account without also controlling your phone or authenticator device. We store 2FA secrets encrypted in our database, and we never transmit them over unencrypted channels.

Our servers are protected by firewalls, intrusion-detection systems, and regular security audits. We monitor for suspicious login patterns—such as logins from multiple countries in a short time or repeated failed password attempts—and alert you immediately if we detect unusual activity. We also require identity verification (KYC) before allowing withdrawals, which prevents unauthorized fund transfers even if an account is temporarily compromised.

Game fairness and RTP

Live-dealer games on sohib—blackjack, roulette, baccarat, Dragon Tiger—are conducted by real croupiers in our studios. You watch the action on camera and can verify outcomes yourself. The dealer's actions are not influenced by software; the cards are dealt from physical decks, and the roulette wheel is a mechanical device. This transparency is the primary advantage of live-dealer gaming over random-number-generator (RNG) games.

RNG-based games like slots (Aviator, Sweet Bonanza, Gates of Olympus, Fortune Tiger, Mahjong Ways) use certified random-number generators to determine outcomes. Return-to-player (RTP) is the percentage of all bets that a game returns to players over a large sample size. Our slot games publish their RTP rates, typically ranging from non-specific info to non-specific info. This means that over thousands of spins, players collectively receive 94–98 cents for every rupiah wagered. Individual sessions will vary wildly—you might win significantly or lose in a single sitting—but the long-term average aligns with the stated RTP.

We submit our games to third-party auditors who verify that our RNG functions correctly and that our payout tables match published rates. These audits are refreshed regularly to maintain transparency. We do not adjust odds based on player behavior or account balance; every spin or hand is independent and equally likely to produce any outcome within the game's design.

KYC verification process

Know-Your-Customer (KYC) verification is a legal requirement that protects both you and sohib. When you open an account, we collect your full name, date of birth, email, and phone number. For transactions above certain thresholds or before your first withdrawal, we request additional documents: a government-issued ID (KTP, passport, or driver's license) and proof of residence (utility bill, bank statement, or lease agreement dated within the last three months).

The verification process typically completes within 24–48 hours, though it may take longer during peak periods or holidays like Idul Fitri or Idul Adha. We accept digital copies of documents (JPEG, PNG, PDF) uploaded directly through your account dashboard. Our compliance team reviews your submission and notifies you once verification is complete. If we need clarification, we'll contact you via email or phone.

We use KYC data to prevent fraud, money laundering, and underage access to our platform. Your personal information is encrypted and stored securely. We do not share your data with third parties except as required by law or to process your payments through our payment partners (DANA, OVO, GoPay, ShopeePay, LinkAja, QRIS, BCA, Mandiri, BRI, BNI). If you have privacy concerns, our legal team can explain how we handle your information in detail.

User feedback and review channels

We encourage players to share feedback about their experience on sohib, including account security, game mechanics, mobile app performance, and customer support. You can leave feedback through your account settings or contact our support team directly via email or live chat. We read all comments and use them to improve our services and identify potential security issues.

When reading reviews of sohib or any gaming platform, look for specific details about what the reviewer experienced—rather than vague praise or complaints. Check multiple sources and note dates, as older reviews may not reflect current conditions. Be wary of reviews that make exaggerated claims ("guaranteed wins," "fastest payouts") or reviews that lack any real detail about the actual experience.

We are transparent about our policies, game mechanics, withdrawal processes, and security practices. If you encounter a discrepancy between what we claim and what you experience, report it immediately to our support team. We take complaints seriously and investigate disputes involving payouts, account access, payment failures, or security concerns. This feedback loop helps us maintain fairness and trustworthiness across the platform.