Tenant Admins and staff
Two-Factor Authentication
Protect your admin console sign-in with an authenticator app and recovery codes, and know what to do if you lose access.
Two-factor authentication (2FA) adds a second step to signing in to the admin console. As well as your password, you enter a 6-digit code from an authenticator app on your phone or password manager. If someone learns your password, they still cannot sign in without that code.
2FA is set up by each person for their own account. It is optional, but we strongly recommend it for everyone on your team, and especially for anyone with the Admin or Finance Manager role.
Before you start
- Any staff member can set up 2FA for their own account. No special permission is needed.
- You need your current password.
- You need an authenticator app that supports time-based one-time codes (TOTP), for example Google Authenticator, 1Password, Authy or a similar app.
- Have somewhere safe to keep your recovery codes, ideally a password manager.
Opening the 2FA page
The page is not in the sidebar. Open the user menu (your avatar in the top corner of the console) and select Two-Factor Authentication.
Turning on 2FA
- Under Enable two-factor authentication, type your current password into the Current password box.
- Select Enable 2FA. The page changes to Finish setup.
- In your authenticator app, add a new account and scan the QR code shown on the page. If you cannot scan it, type the Manual setup key into the app instead. The entry in your app is labelled with your account's name and your email address.
- Type the 6-digit code your app now shows into the box on the page.
- Select Confirm code.
You see "Two-factor authentication enabled" and the page shows Two-factor authentication is active. From your next sign-in onwards you will be asked for a code.
If you get "Invalid authentication code.", wait for your app to show a fresh code and try again. Codes change every 30 seconds, so also check that the time on your phone is set automatically.
If you leave the page before confirming, 2FA is not switched on and your sign-in does not change. The next time you open Two-Factor Authentication you are returned to Finish setup with the same QR code, so you can pick up where you left off.
Saving your recovery codes
Once 2FA is active, the page shows a list of Recovery codes. Each one can be used once, in place of an authenticator code, if you do not have your phone to hand.
Copy them into a password manager or another secure place now. Do not keep them only on the same phone as your authenticator app, or you will lose both together.
The codes stay visible on this page whenever you open it while 2FA is on, so you can check how many you have left. When you use one to sign in, it is replaced automatically, so the list always shows the codes that still work.
Replacing your recovery codes
If you think your codes have been seen by someone else, or you want a fresh set:
- Open Two-Factor Authentication.
- Under Recovery codes, select Regenerate codes.
- Read the warning and select Replace codes.
Your old codes stop working the moment you confirm, including any copies you have saved or printed. Save the new list straight away.
Signing in with 2FA
- Enter your email address and password on the sign-in page and select Sign in.
- An Authenticator code field appears with the message "Enter your authenticator or recovery code to continue."
- Enter the current 6-digit code from your app, or one of your recovery codes.
- Select Sign in again.
If you see "The provided authenticator or recovery code is invalid.", check you are using the entry for this account in your app, and that the code has not just changed.
Turning off 2FA
Turning off 2FA leaves your account protected by its password alone. Your authenticator entry and all remaining recovery codes are destroyed; turning 2FA back on later means scanning a new QR code and saving new codes.
- Open Two-Factor Authentication.
- Under Disable two-factor authentication, type your current password into the Current password box.
- Select Disable 2FA.
- Read the warning and select Turn off 2FA.
You see "Two-factor authentication disabled". If you see "Your current password is incorrect.", re-enter your password in the box and try again.
Moving to a new phone
Do this while you still have your old phone, if you can:
- Sign in to the admin console.
- Turn off 2FA as described above.
- Turn it on again, scanning the new QR code with the app on your new phone.
- Save your new recovery codes.
Some authenticator apps can also transfer their accounts to a new phone for you. If yours does, you do not need to change anything in the console.
If you are locked out
If you have lost your authenticator app, use one of your recovery codes to sign in, then turn 2FA off and on again to set up your new device.
If you have no authenticator and no recovery codes, you cannot turn off 2FA yourself, and your colleagues cannot turn it off for you from the admin console. Resetting your password does not remove 2FA either. Contact Hammerd support to regain access.
If you see "Two-factor authentication data is invalid. Please reset two-factor authentication and try again." when signing in, contact Hammerd support. This is not something you can fix from the sign-in page.
Common questions
Does turning on 2FA affect anyone else on my account?
No. 2FA is set per person. Each member of your team turns it on for their own account.
Does 2FA apply to buyers and sellers on my storefront?
No. This page controls sign-in to the admin console only.
Can I require my whole team to use 2FA?
Not from the admin console today. Ask each staff member to turn it on, and make it part of setting up new staff (see Team members and roles).