Authenticator App - Novaz

Shopify 2FA: How to Set Up an Authenticator App

shopify.com SupportedChecked against official help · September 25, 2026

Your Shopify login opens the Shopify admin for your store, so a leaked password could lead to misdirected payouts. Shopify calls the feature two-step authentication and supports authenticator apps, so Authenticator App - Novaz can generate your one-time codes.

Turning on 2FA for Shopify adds a second layer of protection, so a stolen password alone isn't enough to get in. Besides an authenticator app, Shopify also offers SMS text codes and security keys. An authenticator app (TOTP) is usually the best balance of security and convenience — and it's safer than SMS codes, which can be intercepted through SIM-swap attacks. For the strongest protection, Shopify also supports hardware security keys.

2FA methods Shopify supports

  • SMS text message
  • Authenticator app (TOTP)
  • Security key (U2F / WebAuthn)

Before you start

  • Your Shopify account email address and password (you enter the password again during setup)
  • Your own staff account: each staff member turns on two-step authentication for themselves
  • Authenticator App - Novaz installed on your iPhone or iPad
  • The Shopify admin open on a computer, and a safe place for 10 recovery codes, such as a password manager or a printed copy

Part 1: Turn on 2FA in Shopify

  1. 1

    Open Security in your profile

    From your Shopify admin, click your store name, click your profile, and then click "Security". With the refreshed admin design, your store name may sit elsewhere.

  2. 2

    Click Turn on two-step

    In the "Two-step authentication" section, click "Turn on two-step". Enter your password, and then click "Next".

  3. 3

    Choose Authenticator app

    From the "Authentication method" list, select "Authenticator app". Shopify shows a QR code; leave the page open while you pick up your phone.

Part 2: Add Shopify to Authenticator App - Novaz

  1. 4

    Scan the QR code in Authenticator App - Novaz

    Open Authenticator App - Novaz, tap the + button and scan the QR code. Check that the account name identifies your Shopify login, then tap "Save".

  2. 5

    Note the six-digit code

    Authenticator App - Novaz now shows a six-digit code for Shopify. Use the current one in the next step.

Part 3: Confirm and finish

  1. 6

    Enter the code and click Turn on

    Back in the Shopify admin, enter the six-digit code from Authenticator App - Novaz, and then click "Turn on". From now on, you need your phone to log in.

  2. 7

    Save your 10 recovery codes

    Copy or download your recovery codes and store them in more than one safe place, such as a password manager or on paper. A download is saved as shopify_recovery_codes.txt.

  3. 8

    Optional: add a backup method

    Click "Add another method", enter your password, click "Next", and choose "Shopify Mobile prompts", "Authenticator app" or "Security key". At login you can pick which method to use.

If something goes wrong

  • Shopify rejects the code: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the newest code.
  • Shopify made you set up two-step authentication at login: Shopify or your organization can require it. You need to finish setup to reach the admin, and it can't be turned off while the requirement applies.
  • You can't remove your last method: that's blocked when your organization requires secure sign-in or you have access to financial products.
  • Shopify POS shows a two-step authentication warning: when it's required for your store or account, you may need to complete it in Shopify POS too.

How to recover your Shopify account

Shopify gives you 10 single-use recovery codes during setup; if you can't reach Authenticator App - Novaz, log in with one of them or a backup method. For a fresh list, go to your profile > "Security" and, under "Recovery methods", click "Regenerate codes"; they can only be viewed once. If you've lost your phone and your codes, go to accounts.shopify.com, select "Your store", enter your login details, select "Use a recovery code" (even without codes) and click "Recover my account". Enter the 6-digit code emailed to you (valid for 10 minutes), click "Verify", and verify your identity through Stripe if asked. Shopify reviews the request and emails you the next steps. On Shopify Plus, your organization owner may be able to reset it for you.

Frequently asked questions

Do I need two-step authentication for Shopify Payments?
Yes. Shopify requires two-step authentication to accept payments with Shopify Payments. Without it, your account is less secure and your payouts might be placed on hold.
Can I use text messages instead of an app?
Not for a new setup. SMS can't be added as a new two-step authentication method, though accounts that already use it can keep it. Use an authenticator app, a security key or a built-in authenticator.
How do I move Shopify to a new phone?
Click "Remove" next to your authenticator app, enter your password and click "Next", then set it up again with Authenticator App - Novaz on the new phone. If Shopify won't let you remove your last method, add a backup method first; it becomes primary when the old one is removed.
Can the store owner turn it on for staff?
No. Staff members set up two-step authentication on their own accounts, though Shopify Plus stores can require all users to use a secure sign-in method.

Generate your Shopify codes in Authenticator App - Novaz

Free, offline, and encrypted. One tap for every 6-digit code.

Get the app

More Other guides

Novaz is not affiliated with, endorsed by, or sponsored by Shopify. Shopify and its logo are trademarks of their respective owner and are used here for identification only.