Passkeys & Two-Factor Sign-In
Passkeys & Two-Factor Sign-In
Admin accounts hold your customers, money and staff data. Protect every one of them with two-factor sign-in, and make signing in easier with passkeys. Both work in the admin panel and on the storefront account pages.
Passkeys
A passkey lets you sign in with your device's fingerprint, face unlock, PIN or a hardware security key instead of typing a password. It cannot be phished, because it only works on your real domain.
- Open your profile menu → Settings → Two-factor authentication. Passkeys are managed on the same security screen (customers find it under My Account → Settings).
- Click Add a passkey and follow your browser or phone prompt.
- Give it a name you will recognise, such as "Office laptop" or "Phone".
- Next time, choose Sign in with a passkey on the login page.
Add a passkey on each device you use. Remove a passkey from the same screen if a device is lost. If you do not see the passkey section, passkeys have been switched off for this install by the administrator.
Two-factor authentication
- Open Settings → Two-factor authentication and click Enable.
- Scan the QR code with an authenticator app and enter the six-digit code to confirm.
- Download or copy the recovery codes and keep them offline. Each code works once.
Forgot-password and the two-factor challenge always stay on the back-office host, even when your public website is served by a separate frontend.
For administrators
- Ask every person with an administrative role to enable two-factor in their first week.
- When someone leaves, deactivate their account first, then review the roles they held.
- Public sign-up can be closed for back-office-only installs, so accounts exist only by invitation.

