Skip to main content

Two-Factor Authentication

Two-factor authentication (2FA) adds an authenticator-app code as a second step when logging into your PayRequest dashboard, on top of your regular magic-link/password login.
PayRequest uses passwordless (magic link) authentication for the initial login step, so enabling 2FA does not require re-entering your password to turn on or off — only the authenticator code itself is required to confirm setup.

How It Works

1

Open Security settings

Go to Settings → Security (/settings?tab=2fa).
2

Click Enable

PayRequest generates a TOTP secret and shows a QR code plus a manual setup key.
3

Scan with an authenticator app

Scan the QR code with Google Authenticator (or any TOTP-compatible app) — or enter the setup key manually if you can’t scan.
4

Confirm with a code

Enter the 6-digit code your authenticator app generates to confirm setup. Until you confirm, 2FA isn’t actually active on your account.
5

Save your recovery codes

After confirming, PayRequest generates a set of recovery codes. Store them somewhere safe (a password manager) — each one can be used once to log in if you lose access to your authenticator app.

Logging In With 2FA Enabled

After entering your normal login credentials, you’re prompted for a 6-digit code from your authenticator app. If you don’t have access to your device, you can use one of your recovery codes instead.
Login attempts with a 2FA code are rate-limited to prevent brute-forcing the code.

Managing 2FA

ActionWhat it does
Show Recovery CodesReveals your current set of recovery codes (stored encrypted).
Regenerate Recovery CodesInvalidates your old recovery codes and issues a new set — do this if you suspect a code has been exposed.
DisableTurns off 2FA entirely and removes the stored secret and recovery codes.
Your 2FA secret and recovery codes are encrypted at rest — they’re never stored or displayed in plain text outside of the setup/recovery-codes screen itself.

FAQ

Any standard TOTP app — Google Authenticator, Authy, 1Password, and similar all work since PayRequest uses the standard TOTP protocol.
You won’t be able to complete the 2FA challenge yourself. Contact support to regain access to your account.
No, it’s optional but strongly recommended, especially since your dashboard has access to customer data and payment configuration.
No — 2FA in PayRequest is for your own dashboard login. The customer-facing portal uses its own separate, session-based login.
No. PayRequest uses magic-link (passwordless) authentication, so enabling/disabling 2FA is confirmed with an authenticator code rather than a password.

Next Steps

Audit Logs

See every login and account change

GDPR Compliance

Data protection controls for your account