A Shopify login opens the store: orders, customer details, products and, with Shopify Payments, where your payouts go. Shopify requires two-step authentication to use Shopify Payments and says it helps prevent breaches that lead to misdirected payouts. With it on, a stolen password is not enough — whoever logs in also needs the six-digit code from your authenticator.
Turn on two-step authentication in Shopify
Two-step authentication belongs to your own Shopify login, not to the store: every owner and staff member turns it on in their own profile and gets their own recovery codes. Shopify is rolling out a refreshed admin design, so your store name may sit in a different place than described here.
- Log in to your Shopify admin on your computer and click your store name.
- Click your profile, then click “Security”.
- In the “Two-step authentication” section, click “Turn on two-step”, enter your password and click “Next”.
- From the “Authentication method” list, select “Authenticator app”.
- Shopify shows a QR code. Leave it on the screen and add it to the extension as described below — then enter the six-digit code from the extension and click “Turn on”.
Add Shopify to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Shopify page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Shopify and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Shopify confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Shopify’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeSave your 10 Shopify recovery codes
When you set up two-step authentication, Shopify gives you 10 recovery codes — click “Copy codes”, or “Download codes” to get shopify_recovery_codes.txt. Each code works once. Keep them somewhere other than this computer, ideally in more than one place. If you did not save them, or have used them up, go to Security → Two-step authentication → Recovery methods and click “Regenerate codes”; the new list is shown only once.
The code is not accepted?
Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.
If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Do I need a phone for Shopify two-step authentication?
- No. Shopify’s help lists phone apps such as Google Authenticator and Duo Mobile, but all Shopify checks is the six-digit code, and any standard authenticator produces it. The Authenticator extension reads the QR code straight off the Shopify admin and generates the codes in Chrome.
- Is two-step authentication required on Shopify?
- To use Shopify Payments, yes — Shopify requires it and warns that without it your payouts might be placed on hold. If your organization requires a secure sign-in method, or you have access to Shopify’s financial products, Shopify will not let you remove your last method.
- What if I lose access to my authenticator?
- Log in with a backup method — Shopify Mobile prompts, a second authenticator app or a security key — or with one of your recovery codes. Without any of them, go to accounts.shopify.com, choose “Use a recovery code” and then “Recover my account”: Shopify emails you a code, may ask you to verify your identity, and reviews the request before restoring access.
- Why does Shopify say my code is wrong?
- Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If it still fails, the account may have been added from an old QR code — remove it from the extension and set the authenticator up again.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free