Skip to main content

Documentation Index

Fetch the complete documentation index at: https://mintlify.com/Rahat-Pagecode/gitbook-competitions/llms.txt

Use this file to discover all available pages before exploring further.

Two-factor authentication adds a critical second layer of protection to your admin account. Once enabled, logging in from an unrecognised device will require a time-based one-time code from your authenticator app before access is granted — meaning a stolen password alone is not enough to compromise your account. The platform supports any TOTP-compatible authenticator app, including Authly and Google Authenticator.

Enabling 2FA on Your Account

1

Open Your Profile Settings

Log in to your website and click your profile name in the top-right corner of the admin area to open your account settings.
2

Find the Admin 2FA Section

Scroll down until you see the Admin 2FA section.
3

Enable and Save

Check the Enable checkbox and save your changes. A QR code will appear on the page.
4

Scan the QR Code

Open your authenticator app (Authly, Google Authenticator, or any other TOTP app) and scan the QR code. Your phone’s camera may open the authenticator automatically — follow the prompts to add the account.
5

Verify the Setup

Log out of your account and log back in. You will be prompted to enter the 6-digit code shown in your authenticator app. Entering the correct code confirms that 2FA is working correctly.
Once you log in successfully from a device, that device is remembered as trusted for 30 days. You will not be asked for a 2FA code again on that device until the trust period expires.

Managing Trusted Devices

You have full control over which devices are trusted on your account:
  • You will only be asked for a 2FA code on unrecognised devices — trusted devices pass through automatically during the 30-day window.
  • You can forget all trusted devices at any time, forcing 2FA to be re-verified on every device at next login.
  • You can also revoke individual trusted devices if, for example, you no longer use a particular phone or computer.

Forcing 2FA for All Admins and Shop Managers

If your site has multiple admin users or shop managers, you can require all of them to set up 2FA before they can access any sensitive pages. Enable this option under Extensions in your admin settings. Once enforced, any admin or shop manager who has not yet configured 2FA will see a restriction notice when they attempt to access a protected page. The notice redirects them to the 2FA setup section under their own profile, where they must complete setup before access is restored.
Until a team member completes their 2FA setup, they will be blocked from viewing sensitive admin pages. Make sure all team members are aware of the requirement before you enable forced 2FA.

Build docs developers (and LLMs) love