Two-Factor Authentication
Two-factor authentication (2FA) adds an authenticator-app code as a second step when logging into your PayRequest dashboard, on top of your regular magic-link/password login.PayRequest uses passwordless (magic link) authentication for the initial login step, so enabling 2FA does not require re-entering your password to turn on or off — only the authenticator code itself is required to confirm setup.
How It Works
Scan with an authenticator app
Scan the QR code with Google Authenticator (or any TOTP-compatible app) — or enter the setup key manually if you can’t scan.
Confirm with a code
Enter the 6-digit code your authenticator app generates to confirm setup. Until you confirm, 2FA isn’t actually active on your account.
Logging In With 2FA Enabled
After entering your normal login credentials, you’re prompted for a 6-digit code from your authenticator app. If you don’t have access to your device, you can use one of your recovery codes instead.Managing 2FA
| Action | What it does |
|---|---|
| Show Recovery Codes | Reveals your current set of recovery codes (stored encrypted). |
| Regenerate Recovery Codes | Invalidates your old recovery codes and issues a new set — do this if you suspect a code has been exposed. |
| Disable | Turns off 2FA entirely and removes the stored secret and recovery codes. |
Your 2FA secret and recovery codes are encrypted at rest — they’re never stored or displayed in plain text outside of the setup/recovery-codes screen itself.
FAQ
Which authenticator apps work?
Which authenticator apps work?
Any standard TOTP app — Google Authenticator, Authy, 1Password, and similar all work since PayRequest uses the standard TOTP protocol.
What happens if I lose my phone and my recovery codes?
What happens if I lose my phone and my recovery codes?
You won’t be able to complete the 2FA challenge yourself. Contact support to regain access to your account.
Is 2FA required?
Is 2FA required?
No, it’s optional but strongly recommended, especially since your dashboard has access to customer data and payment configuration.
Does 2FA apply to my customers logging into the customer portal?
Does 2FA apply to my customers logging into the customer portal?
No — 2FA in PayRequest is for your own dashboard login. The customer-facing portal uses its own separate, session-based login.
Do I need to re-enter my password to enable or disable 2FA?
Do I need to re-enter my password to enable or disable 2FA?
No. PayRequest uses magic-link (passwordless) authentication, so enabling/disabling 2FA is confirmed with an authenticator code rather than a password.
Next Steps
Audit Logs
See every login and account change
GDPR Compliance
Data protection controls for your account