Two-step authentication using Shopify mobile prompts as a backup method
Shopify mobile prompts uses a mobile device to receive a message when you log in that asks you to confirm that you are trying to log in to your account.
Shopify mobile prompts can only be used as a backup two-step authentication method. You must set up one of the following authentication methods as your primary method:
The Shopify app must be installed on the mobile device that you use for Shopify mobile prompts.
On this page
Benefits of Shopify mobile prompts
It's recommended to use Shopify mobile prompts instead of text message (SMS) verification codes to help you secure your account for the following reasons:
- Attackers might try and steal authentication codes sent through SMS. Shopify mobile prompts help protect you against attackers by sending them more securely to only your signed in devices.
- Shopify mobile prompts give more information on any login attempts to your account. This information includes the device, location, and time.
- You can quickly block suspicious activity using Shopify mobile prompts. If you didn’t try to sign in to your account, then tap No on the notification to secure your account.
Before you begin
Before you set up Shopify mobile prompts, make sure that you complete the following:
Set up a primary authentication method.
Install the Shopify app on the mobile device that you use for Shopify mobile prompts. If you already have the Shopify app installed on your mobile device, make sure that you have the most recent version.
Log in to the Shopify app on that device.
Set up Shopify mobile prompts
Log in to the Shopify app on the mobile device that you want to use to receive push notifications.
From your Shopify admin, click your store name in the topbar.
Click Manage account > Security.
In the Two-step authentication section, click Add another method.
Enter your password, and then click Next.
From the Authentication method list, select Shopify Mobile prompts.
-
Select the mobile device that you want to use to receive notifications. If your device isn't on the list of available devices, then verify the following:
- You have the most recent version of the Shopify app installed on your mobile device.
- You're logged in to the Shopify app on that device.
-
If your device wasn't on the available list, then after you log in to the Shopify app on that device, you need to perform the following steps again:
- In the Two-step authentication section, click Add another method.
- Enter your password, and then click Next.
- From the Authentication method list, select Shopify Mobile prompts.
- Select the mobile device that you want to use to receive notifications.
Click Send mobile prompt. A test message is displayed on the device that you selected.
On your mobile device, tap Approve. You receive an email message that states that you have activated Shopify Mobile prompt as a backup method.
From your Shopify admin, click Complete.
-
Save your recovery codes in case you're unable to use your primary or backup authentication method. Make sure that you store or save the recovery codes in multiple ways, including the following examples:
Now when you log in, you can use your mobile device for two-step authentication.
Activate two-step authentication notifications
If you don't receive notifications after you set up Shopify mobile prompts, then you might need to verify that you have activated Security updates and Multi-factor authentication for the Shopify app on your mobile device.
Steps:
iOS
- From the Shopify app, tap the … button, and then tap Settings.
- In the App settings section, tap Account notifications.
- Verify that Security notifications and Two-factor authentication are activated.
Android
- From the Shopify app, tap the … button, and then tap Settings.
- In the App settings section, tap Account notifications.
- Verify that Security updates and Multi-factor authentication are activated.
- Tap OPEN SETTINGS.
- Verify that Security updates and Multi-factor authentication are activated.