How to enable or disable two-factor authentication
Two-factor authentication (2FA) adds a 6-digit Authenticator code after your password at sign-in. NextShopper supports authenticator apps (Google Authenticator, 1Password, Authy, and similar). When enabled, stolen passwords alone should not open your portal. Home may nudge you with Set up 2FA.
This guide covers Enable 2FA, confirming with the first code, daily sign-in with Verify, and Disable 2FA.
Who this guide is for
- Customers protecting domains and billing
- Users who saw the Home banner Turn on two-factor authentication…
- Anyone changing phones and needing to disable/re-enable cleanly
Before you start
- Install an authenticator app on a device you control.
- Sign in to Account.
- Prefer enabling on a trusted network/device.
- Store recovery planning: if you lose the app, you will need support identity checks.
Step-by-step: enable 2FA
- Open Account → Two-factor authentication.
- Read the help: after enable, each sign-in asks for a 6-digit authenticator code.
- Select Enable 2FA and follow on-screen pairing (QR / secret as shown).
- Enter Enter the first code from the app / Authenticator code.
- Confirm status Two-factor authentication is on. / Authenticator app is enabled for this account.
Step-by-step: sign in with 2FA
- Enter email and password on Sign in.
- When challenged, open your app and enter the current code.
- Select Verify.
- Use a fresh code if one fails (codes rotate about every 30 seconds). Keep device time automatic.
Step-by-step: disable 2FA
- Open Account → Two-factor authentication.
- Select Disable 2FA and confirm any code/password challenge shown.
- Confirm Two-factor authentication is off.
Re-enable after moving to a new phone.
What happens next / how to verify success
- Enabled: next login requires a code; Home 2FA nudge clears.
- Disabled: password-only login returns (less secure).
- Recent sign-ins still lists successful sessions.
Common problems
| Problem | What to try |
|---|---|
| Invalid code | Wait for next code; fix device clock; re-pair if needed |
| Lost authenticator | Contact support from account email with invoice proof—never post backup codes publicly |
| Enable fails | Retry; ticket if QR never appears |
| Prompted unexpectedly | 2FA is on—use the app or disable only on a trusted session |
| SMS expected | NextShopper 2FA here is authenticator-app based |
Frequently asked questions
Is 2FA mandatory?
Optional, but strongly recommended for domain portfolios.
Does 2FA affect mailbox login?
No—only the client portal account.
Can I use hardware keys?
Follow what the Account UI offers; authenticator apps are the documented path.
Will staff ask for my 2FA codes?
Never share live codes in email. Staff will use identity verification instead.
Related guides
- How to sign in to the client portal
- How to change your password
- How to use the Home dashboard
- How to export your data or request account erasure
Still need help?
If you are locked out of 2FA, use Contact from the account email with recent invoice numbers. If you can sign in, prefer a support ticket.