Bancoli offers more than one social login, including Google and LinkedIn. Google is a strong choice for wallet operations when you turn on Advanced Protection and keep the rest of your Bancoli access off that same Google account.
Access to a Google account does not, by itself, open your wallet. That is the point of the extra layers. Besides the social login you use for wallet operations, someone still needs your Bancoli login and your 2FA code.
The real risk is putting all four (2 logins, 2FA) on the same account. If you use the same account to sign in to Bancoli, to create the wallet, and for Google Authenticator for your 2FA codes, the four layers become one. For this reason, our systems require using a different account for your Bancoli sign-in and wallet creation.
We recommend the steps below before you fund the account. Completing them does not change which Bancoli products, rails, or prices are available to you.
1. Keep the layers on different systems
Treat these as separate controls:
Your Bancoli login
The social login used for wallet operations
Your Bancoli 2FA code
Your wallet 2FA code
A common setup is Google with Advanced Protection for the wallet, and a different method for the Bancoli login, such as LinkedIn or email. Keep 2FA codes somewhere that is not only inside that same Google account.
Do not use this combination:
Google sign-in for Bancoli
Google sign-in for wallet creation
2FA codes stored only in Google Authenticator for Bancoli
2FA codes stored only in Google Authenticator for your wallet
That setup looks like four steps. It is one Google account.
2. If you use Google for the wallet, turn on Advanced Protection
If Google is your wallet social login, turn on Advanced Protection. It requires a passkey or a security key to sign in. Someone who knows the password still cannot open the Google account without that key.
Before you enroll:
Turn on 2-Step Verification on the Google account.
Add a recovery email and a recovery phone.
Set up a passkey or a security key, plus one backup stored in a separate place.
Then enroll at Google Advanced Protection.
After enrollment:
Sign-in requires a passkey or security key.
Apps that use app passwords are blocked.
Only Google apps and verified third-party apps can access the account, and only with your permission.
If more than one person must sign wallet payments, enroll one signer first. Confirm they can still open the wallet and complete a low-value signed action. Confirm the recovery path. Then enroll the rest.
3. Clean up that Google account
Review the Google account you use for wallet operations before you send or receive live payments.
Use a recovery email that is not another Gmail address on the same Google account. Keep it company-owned if a team must recover access.
Review recent devices and sign-ins. Sign out of anything you do not recognize.
Remove old third-party apps that still have access to Gmail.
Turn off SMS as a Google sign-in method where you can. Use a passkey, security key, or authenticator app instead.
You can review this in Google account security.
Prefer a company-owned Google account if more than one person must sign payments. A personal founder Gmail means only that founder can complete the Google step.
What Bancoli will never ask for
Bancoli will not ask you for a Google password, a LinkedIn password, a passkey, or a one-time code by email or chat. If a message asks for those, do not reply. Sign in at app.bancoli.com or contact Bancoli Support through chat or a support ticket.
This page is about using Google well as one social login, and keeping it from becoming your only control. It is not a guide to Bancoli password reset, Bancoli 2FA reset, or which payment methods appear after approval.
