One self-hosted console to run your entire business — commerce, ERP, HRM, CRM & manufacturing

Passkeys & Two-Factor Sign-In

Passkeys & Two-Factor Sign-In

Admin accounts hold your customers, money and staff data. Protect every one of them with two-factor sign-in, and make signing in easier with passkeys. Both work in the admin panel and on the storefront account pages.

Passkeys

A passkey lets you sign in with your device's fingerprint, face unlock, PIN or a hardware security key instead of typing a password. It cannot be phished, because it only works on your real domain.

  1. Open your profile menu → Settings → Two-factor authentication. Passkeys are managed on the same security screen (customers find it under My Account → Settings).
  2. Click Add a passkey and follow your browser or phone prompt.
  3. Give it a name you will recognise, such as "Office laptop" or "Phone".
  4. Next time, choose Sign in with a passkey on the login page.

Add a passkey on each device you use. Remove a passkey from the same screen if a device is lost. If you do not see the passkey section, passkeys have been switched off for this install by the administrator.

Two-factor authentication

  1. Open Settings → Two-factor authentication and click Enable.
  2. Scan the QR code with an authenticator app and enter the six-digit code to confirm.
  3. Download or copy the recovery codes and keep them offline. Each code works once.

Forgot-password and the two-factor challenge always stay on the back-office host, even when your public website is served by a separate frontend.

For administrators

  • Ask every person with an administrative role to enable two-factor in their first week.
  • When someone leaves, deactivate their account first, then review the roles they held.
  • Public sign-up can be closed for back-office-only installs, so accounts exist only by invitation.
Last updated: 10/5/2026