Two-Factor Authentication
Two-factor authentication (2FA) adds an authenticator-app code as a second step when logging into your PayRequest dashboard, on top of your regular magic-link/password login.PayRequest uses passwordless (magic link) authentication for the initial login step, so enabling 2FA does not require re-entering your password to turn on or off β only the authenticator code itself is required to confirm setup.
How It Works
1
Open Security settings
Go to Settings β Security (
/settings?tab=2fa).2
Click Enable
PayRequest generates a TOTP secret and shows a QR code plus a manual setup key.
3
Scan with an authenticator app
Scan the QR code with Google Authenticator (or any TOTP-compatible app) β or enter the setup key manually if you canβt scan.
4
Confirm with a code
Enter the 6-digit code your authenticator app generates to confirm setup. Until you confirm, 2FA isnβt actually active on your account.
5
Save your recovery codes
After confirming, PayRequest generates a set of recovery codes. Store them somewhere safe (a password manager) β each one can be used once to log in if you lose access to your authenticator app.
Logging In With 2FA Enabled
After entering your normal login credentials, youβre prompted for a 6-digit code from your authenticator app. If you donβt have access to your device, you can use one of your recovery codes instead.Managing 2FA
Your 2FA secret and recovery codes are encrypted at rest β theyβre never stored or displayed in plain text outside of the setup/recovery-codes screen itself.
FAQ
Which authenticator apps work?
Which authenticator apps work?
Any standard TOTP app β Google Authenticator, Authy, 1Password, and similar all work since PayRequest uses the standard TOTP protocol.
What happens if I lose my phone and my recovery codes?
What happens if I lose my phone and my recovery codes?
You wonβt be able to complete the 2FA challenge yourself. Contact support to regain access to your account.
Is 2FA required?
Is 2FA required?
No, itβs optional but strongly recommended, especially since your dashboard has access to customer data and payment configuration.
Does 2FA apply to my customers logging into the customer portal?
Does 2FA apply to my customers logging into the customer portal?
No β 2FA in PayRequest is for your own dashboard login. The customer-facing portal uses its own separate, session-based login.
Do I need to re-enter my password to enable or disable 2FA?
Do I need to re-enter my password to enable or disable 2FA?
No. PayRequest uses magic-link (passwordless) authentication, so enabling/disabling 2FA is confirmed with an authenticator code rather than a password.
Next Steps
Audit Logs
See every login and account change
GDPR Compliance
Data protection controls for your account