# Account data formats: login, password, 2FA, token, cookie, and JSON

> These labels are not interchangeable: each describes a different credential, recovery method, or data container.

## Login and password

These are ordinary sign-in credentials. A password does not imply that a recovery email, phone number, or second factor is included; check the exact product page.

## 2FA and recovery data

2FA is an additional check after the password. The product page should say which second factor or secret is included; the label 2FA alone does not promise access to a phone number or recovery mailbox.

## Token, cookie, and session

A token grants an application scoped or session access, a cookie lets a website remember a browser session, and a session file stores client state. Any of them can be as sensitive as a password and must not be shared.

## JSON and Base64

JSON is a text data structure, while Base64 represents bytes as text characters. Base64 is not encryption: decoded content may still contain secrets. Never upload delivered files to an unknown online decoder.

## Related

- [What 2FA means and how to enable it safely](https://getproaccs.com/en/docs/two-factor-authentication)
- [Cookie, JSON, and Base64: the difference](https://getproaccs.com/en/docs/cookies-json-and-base64)
- [Token, refresh token, and OAuth 2.0 explained](https://getproaccs.com/en/docs/tokens-and-oauth)
- [Safe first inspection of a digital account](https://getproaccs.com/en/docs/first-access-security)

## Sources

- [RFC 8259: JSON](https://www.rfc-editor.org/rfc/rfc8259)
- [RFC 4648: Base64](https://www.rfc-editor.org/rfc/rfc4648)

Canonical: https://getproaccs.com/en/docs/account-data-formats
Updated: 2026-10-11
