How to Set Up an Authenticator App for Shopify

Written by: Abigail Ivy
Published on:

Setting up an authenticator app for Shopify adds an extra login layer that protects your store even if a password is stolen.

This guide explains how to set it up, which apps to use, and how to avoid common mistakes that lock merchants out.

What an authenticator app does in Shopify

An authenticator app generates time-based one-time codes, usually six digits, that expire every 30 seconds.

Shopify uses these codes as part of two-step authentication, also called two-factor authentication or 2FA, to verify that the person signing in has both the password and the device that holds the app.

This is especially important for online stores because Shopify accounts often have access to payment settings, customer data, themes, apps, and staff permissions.

If an attacker gets a password through phishing, credential stuffing, or reuse from another breach, an authenticator app can stop the login attempt.

Before you begin

To reduce setup issues, prepare the following:

  • A smartphone or tablet that can install an authenticator app.
  • Access to your Shopify admin account.
  • A secure backup method, such as recovery codes or a second trusted device.
  • A password manager, if you want to store backup codes safely.

Popular authenticator apps include Google Authenticator, Microsoft Authenticator, Authy, and 1Password.

Any app that supports time-based one-time passwords (TOTP) should work with Shopify.

How to set up authenticator app for Shopify

The setup process is straightforward, but the exact labels may vary slightly depending on whether you are using the desktop admin or the Shopify mobile app.

1. Sign in to Shopify admin

Log in to your Shopify admin using the account that will control security settings.

If you manage multiple staff accounts, start with the owner account or the account that has permission to manage security.

2. Open account security settings

From the Shopify admin, go to your profile or account area and locate security or two-step authentication settings.

Shopify typically places these options under your account profile, where you can manage login methods and verification settings.

3. Turn on two-step authentication

Choose the option to enable two-step authentication.

Shopify may present several verification methods, such as an authenticator app, SMS, or security key.

For the strongest practical protection, select an authenticator app or security key instead of SMS.

4. Choose authenticator app as the method

Select authenticator app when prompted.

Shopify will display a QR code and sometimes a manual setup key.

The QR code is the easiest method because it automatically adds your Shopify account to the app.

5. Add the account in your authenticator app

Open your authenticator app on your phone, tap the option to add a new account, and scan the QR code from Shopify.

If scanning is not possible, enter the setup key manually.

The app should immediately begin generating rotating codes for Shopify.

6. Enter the verification code in Shopify

Type the current six-digit code from the authenticator app into Shopify to confirm the connection.

Because the code changes frequently, make sure you enter it before it expires.

If the code fails, wait for a fresh one and try again.

7. Save recovery codes

Shopify usually provides recovery or backup codes after enabling two-step authentication.

Save these immediately in a secure location.

Recovery codes are essential if you lose your phone, delete the app, or cannot access your authenticator for any reason.

Which authenticator app is best for Shopify?

Shopify works with most TOTP-based authenticator apps, so the best choice depends on your workflow and backup needs.

  • Google Authenticator: Simple and widely used, but backup options are limited compared with some competitors.
  • Microsoft Authenticator: Good for users already in the Microsoft ecosystem and supports cloud backup on supported devices.
  • Authy: Known for multi-device support and recovery features, which can be useful for merchants with multiple devices.
  • 1Password: Combines password management and 2FA codes in one place, which can simplify secure access for teams.

For businesses, the best option is often the one that balances convenience, device backup, and team policy.

If your staff share access to key Shopify systems, use a standard process so codes are not scattered across personal devices without documentation.

How to keep Shopify login secure after setup

Turning on an authenticator app is only one part of account security.

To reduce the risk of account compromise, follow these practices:

  • Use a unique, long password for Shopify.
  • Store passwords in a trusted password manager.
  • Avoid using SMS as your primary 2FA method if an authenticator app is available.
  • Limit staff permissions to only what each person needs.
  • Review installed apps and remove unused integrations.
  • Watch for phishing emails that imitate Shopify notifications.

Shopify also supports security keys for stronger authentication.

For high-risk accounts, especially those with large sales volume or access to financial settings, combining a security key with a strong password policy can further reduce risk.

How to handle a lost phone or changed device

If you lose the device that holds your authenticator app, recovery depends on the backup steps you took during setup.

Start by trying your recovery codes or signing in from a trusted browser or device if that option is available.

If you use a cloud-synced authenticator app, restore the app on the new device before attempting to log in.

If you do not have backup access, contact Shopify support and be ready to verify account ownership.

This process can take time, so recovery codes are critical for business continuity.

To prevent downtime in the future, keep at least one backup method available and document where the recovery codes are stored.

Many teams also designate a secondary admin so one lost device does not block access to the store.

Common setup problems and fixes

The QR code does not scan

Increase screen brightness, hold the phone steady, and make sure the QR code is fully visible.

If the camera still fails, use the manual setup key instead.

The code is marked invalid

Authenticator codes are time-sensitive.

Make sure your phone’s clock is set automatically and enter the current code before it expires.

If needed, wait for the next code and try again.

You cannot find the security setting

Shopify periodically updates the admin interface.

Search for account security, two-step authentication, or login settings in your profile area.

If you manage a staff account, permissions may limit what you can see.

You enabled the app but still get prompted for another method

Shopify may require additional verification for certain devices, sign-ins, or admin actions.

This is normal if your account has multiple security methods enabled.

Best practices for teams and agencies

If you run a Shopify store with staff, freelancers, or a marketing agency, create a written security policy.

It should define who can access the account, how 2FA is set up, where recovery codes are stored, and how ownership transfers are handled when someone leaves the team.

For agencies managing multiple Shopify stores, separate credentials by client and avoid reusing the same password or authenticator setup across accounts.

Use staff roles, collaborator access, and least-privilege permissions to reduce exposure.

  • Assign two or more trusted admins for critical stores.
  • Store recovery codes in a secure shared vault, not chat messages.
  • Remove access immediately when contractors finish work.
  • Audit login methods after major staff changes.

When to upgrade beyond an authenticator app

An authenticator app is a strong baseline, but some stores need more.

Consider a security key if you handle high-value transactions, manage multiple brands, or want phishing-resistant login protection.

Security keys use hardware-based authentication such as FIDO2 or WebAuthn and are harder to intercept than codes from an app.

Even if you stay with an authenticator app, you can strengthen your setup by pairing it with secure device practices, current operating systems, and careful role management inside Shopify.