Two-factor protects administrator sign-in, which is the account that can issue refunds, read every customer record and change payment settings. It is the highest-value control in the product and takes ten minutes.

Plan recovery before you enable it.

The failure mode is not a security breach, it is being locked out of your own billing system on a Sunday. Decide now how an administrator who loses their phone gets back in.

Enable it

  1. Open Settings → Two-Factor Authentication.
  2. Enable the mechanism you want. A time-based authenticator app is the usual choice and needs no external service.
  3. Decide whether it is required for all administrators or optional. Required is right; optional means the account that matters most is the one that skipped it.
  4. Save.

Enroll your own account first

  1. Open your own administrator profile and start two-factor setup.
  2. Scan the code with an authenticator app.
  3. Enter the generated code to confirm the pairing.
  4. Save the backup codes somewhere that is not the phone you just paired. A password manager or a safe, not a note on the same device.
  5. Sign out completely and sign back in, to prove it works before anyone else depends on it.

Enroll the team

  1. Tell people it is coming and what app to install, before you make it required.
  2. Enroll a second full administrator and confirm they can sign in independently.
  3. Only then make it required for everyone.
Keep at least two recoverable full administrators.

One super-administrator with two-factor and no recovery path is a single point of failure for the whole business.

When somebody is locked out

  1. They use a backup code, if they kept them.
  2. Otherwise another full administrator disables two-factor on their account, they sign in, and they re-enroll immediately.
  3. If nobody can sign in at all, recovery is a database-level operation, which means downtime and a support conversation. This is the situation the second administrator exists to prevent.

What it does not cover

Two-factor protects interactive sign-in. It does not protect API credentials, which authenticate without a person — restrict those by role and by address instead. See Create API credentials. It also does not protect customer accounts in the client area; that is a separate setting.