First login and token generation
When you open maxwin4d on your phone for the first time, you enter your email and password. We validate these credentials against our database, check for any account flags or security holds, and generate a session token unique to your device. This token includes your device identifier (a hash of your phone's hardware ID), your account ID, and an expiry timestamp set 24 hours in the future.
We transmit the token over an encrypted connection (HTTPS) and store it in your device's secure storage—on Android, this is the Android Keystore; on iOS, this is the Secure Enclave. Your password is never stored on your phone. Only the token persists, and only if you remain logged in.
After login succeeds, we display your dashboard—Liga 1 matches, live-dealer tables, slot games, and esports markets fill your home screen. Your account balance appears in the top-right corner, and we show your recent transaction history if you tap AccountAll of this data syncs from our servers in real-time.
The token refresh happens automatically. Every time you interact with maxwin4d—spinning a slot, placing a bet on Piala AFF, joining a blackjack table—we validate your token against our session store. If the token is valid and not expired, the action proceeds. If it has expired (24+ hours of inactivity), we clear it from your device and ask you to log in again.
Device verification and account security
When you log in from a new device for the first time, we flag it for verification. We send a one-time code (OTC) to your registered email address or phone number. You enter this code in the app, and we verify it matches our record. Once verified, the device is marked as trusted for 30 days—you will not need to re-enter the OTC on this device during that window.
This process protects your account from unauthorized access. If someone else obtains your password but tries to log in from a different phone, they cannot proceed without the OTC. Even if they intercept the OTC, we log the login attempt and send you an alert email. You can review all recent login attempts in your Account > Security tab anytime.



Session management across devices
maxwin4d supports simultaneous sessions on multiple devices. You can be logged in on your Android phone, your iPad, and your desktop browser at the same time. Each device maintains its own session token, and each token is validated independently. Your account balance, transaction history, and game progress sync across all devices in real-time.
If you initiate a withdrawal on your phone, you will see the withdrawal status update on your desktop browser within seconds. If you deposit via DANA on your tablet, your balance increases on your phone instantly. We use a centralized account ledger to ensure consistency—no orphaned transactions or conflicting data.
-
1
Download maxwin4d app or open browserInstall
Android: download the APK from maxwin4d.bet/app. iOS: open Safari and bookmark maxwin4d.bet, or download from the App Store if available in your region.
-
2
Enter credentialsAuthentication
Type your email and password. We validate them against our database and generate your session token.
-
3
Verify device (first time only)New device
If this is a new device, we send a one-time code to your email. Enter it to verify. We mark the device as trusted for 30 days.
-
4
Access your dashboardReady
You see your account balance, upcoming Liga 1 fixtures, available blackjack tables, and slot games. You can deposit via e-wallet, mobile banking, local payment, or bank VA immediately.
-
5
Return to app—Quick Login skips credentialsFuture visits
Next time you open maxwin4d on this device, your session token is already valid. We check the token, verify the device, and log you in automatically.
Manual logout and session termination
If you want to log out manually, tap Account > Logout at the bottom of the menu. We delete your session token from your device immediately. Your next visit requires you to re-enter your email and password. Manual logout is recommended if you are sharing your phone with family or if you suspect your account security is compromised.
If you lose your phone or it is stolen, log in from another device and go to Account > Security > Revoke All DevicesWe instantly expire all session tokens on all devices. Any attacker with your old phone cannot access your account—they will be forced to log in with your password, and we will send you an alert email if they try.
Key takeaways
- Quick Login on maxwin4d uses session tokens stored securely on your device, not passwords
- Session tokens expire after 24 hours of inactivity; we refresh them automatically when you interact with the platform
- New devices require one-time code verification; trusted devices skip this step for 30 days
- You can be logged in simultaneously on multiple devices; your balance and history sync in real-time
- Manual logout and device revocation protect your account if your phone is lost or stolen
Password reset and account recovery
If you forget your password, tap Forgot Password on the login screen. We send a password reset link to your registered email address. The link expires after one hour for security. Click it, enter your new password (minimum 8 characters, mixed case and numbers recommended), and confirm. We log out all existing sessions on all devices when you reset your password.
If you cannot access your registered email, contact our support team. They verify your identity using your account details—registered phone number, KYC documents, recent transaction history—and help you regain access. Support responds within two hours during business hours. During Idul Fitri or Idul Adha holidays, response time may extend to four hours.
Your account stays secure throughout this process. We never email your password or share account details with third parties. All recovery communications flow through encrypted channels, and we log every recovery attempt for fraud detection.
