Early 2023, we rolled out a change to increase the security of your Shopify Payments account, and your Shopify Account as a whole. In order to increase account security for our users, we’ve made it a requirement for store owners that have enabled, or will enable, Shopify Payments, to have two-factor authentication enabled.
I wanted to create a resource to help explain the purpose of two-factor authentication, and the value that it brings to you as a merchant.
Two-Step Authentication adds an extra layer of account security to your account. If a bad actor were to gain access to the login information you use for your account, or access to the email address you use for your account, they won’t be able to login. This is because they won’t have access to the tool you use for the extra layer of security that enables 2-factor authentication.
Types of Two-Factor Authentication
When it comes to setting up Two-Factor Authentication for your own store and account, there are different methods of enabling this extra layer of security. I’m going to take some time to explain these different available options, that way you can determine which one would work best for you.
Authenticator Application (Recommended Method)
Dataprot.net reports that push notification via authenticator app is the most commonly used method of 2FA (Two-Factor Authentication), with 68% of all 2FA users opting into this method. It involves downloading an application to a mobile device, such as Microsoft Authenticator, or Google Authenticator. Once downloaded, you can scan a QR code with your device that is provided by the service that you’re securing, and then it syncs a code up to your store.
Whenever you attempt to login to your store, the app will send you a push notification that you can open to approve the login, or open to collect the code that needs to be entered.
I use this method for many accounts on different services and find that it’s always worked fantastic for me.
SMS Code
This method involves receiving a code to your phone number. When setting up 2FA, you can opt to provide a number that an SMS message (a text message) can be sent to. Whenever you attempt to login, a text will be sent providing you with a code to be entered on the device you’re logging into.
Security Key
A Security Key is a piece of security hardware that you can use to verify your identity when logging into your account. A popular device used for this includes YubiKey. You can also use your phone as a Security Key, where the device will ask you to scan a QR code and then verify your identity on your phone via a pin or other method. This method works well, but if you leave your security key somewhere else, you won’t be able to login as easily!
Built-in Authentication
You can leverage the built-in authentication methods available on your devices to confirm your identity. If your mobile phone has a fingerprint sensor, for example, then you can have your fingerprint be required as 2FA in order to login.
Shopify Mobile Prompt
Finally, the final method you can use to set up 2FA for your Shopify Account is the Shopify Mobile App Prompt. This method will prompt you via the Shopify Mobile App when your account is logged in on a different device.
There are other methods of 2-Factor Authentication out there, but we wanted to highlight these options as these are the ones related to securing your Shopify Account. If you’re curious about learning more, check out this page from Dataprot.Net!
How to Set up 2-Factor Authentication for your Store
Below, I’ve outlined the steps on how to activate 2FA on your desktop device, so you can sync your account with your mobile device. I’ve provided screenshots of how the set-up process works while completing this task on a desktop using the ‘‘Authentication App’ method. We’ll be outlining this method as it’s the one we recommend in this tutorial. If planning on using a different method, follow along with the prompts that appear on screen.
1.) Login to your Shopify Admin
2.) Go to Account Name or Email in the top right corner
3.) Click on your name/email
4.) Select ‘Manage Account’ from the drop-down that appears.
A new page will load showing you some general account options. A small menu should appear on the left side of your screen. On that left side, select the ‘Security’ option that appears.
Once that’s done, you’ll be on a new page listing several different security options for you to consider. For now, let’s scroll down and focus on the section titled ‘Two-Step Authentication’. In the ‘Authentication Methods’ box, click on the button that says ‘Turn On Two-Step’.
After clicking “Turn on two-step” , a pop-up window will appear and provide you with options for 2-Factor Authentication. Select the ‘Authenticator App’ option.
Once selected, you will be presented with some information and a QR code. You’ll want to use your newly downloaded Authenticator App (here’s a link to Google Authenticator and Microsoft Authenticator) to scan the QR code. When you scan it, you’ll want to enter the 6-digit code that appears on your device into the bar asking for it. Enter that code, and hit the ‘Turn On’ Button.
Once you’ve turned on 2FA, you’ll be prompted to save your Recovery Codes. It is incredibly important that you save these codes somewhere, either in a physical form, or download them to your device.
These codes will help you access your account if you’re ever unable to get that 2FA code. We’ve seen an increase in folks reaching out to our live Support teams due to not having access to these codes, so make sure that you save them somewhere!
Conclusion
That caps off how to set up Two-Factor Authentication for your store! I do hope that you found this walkthrough helpful! Feel free to leave us any feedback in the comments! Happy (safe and secure) selling!





