Multi-factor authentication (MFA), also called two-factor authentication (2FA), protects a ShipHero user's login by asking for a verification code from an authenticator app in addition to their password. Admins can turn MFA on or off for one user at a time, or turn it on for several users at once from the Users page.
Before You Begin
- Required user role permission: Only users with the Admin role or the Edit Users permission can enable or disable MFA, for themselves or for other users.
- Authenticator app required: ShipHero does not support MFA by email. Each user needs an authenticator app, such as Google Authenticator, Microsoft Authenticator, or the Passwords app on iPhone.
- Users with API tokens: Enabling MFA for a regular user stops that user's API tokens from working. To keep API access, leave MFA off for that user, or use a developer user instead. See How to Obtain API Access and Refresh Tokens.
Table of Contents
- How MFA Works in ShipHero
- How to Enable or Disable MFA for ShipHero Users
- How to Register a Device for ShipHero MFA
- Staying Signed In to ShipHero: Remember This Device
How MFA Works in ShipHero
ShipHero MFA is adaptive. A user with MFA turned on is only asked for a code when a login looks suspicious, such as a sign-in from a new device or an unusual location.
- Refunds: MFA is also required for sensitive actions. Issuing a refund triggers an MFA prompt on the first refund of each day.
- API tokens: A regular user with MFA turned on cannot use their API tokens. Use a developer user for API access instead.
How to Enable or Disable MFA for ShipHero Users
MFA is set on each user's profile. Change it for one user from their profile, or enable it for several users at once from the Users page.
When you disable and then re-enable MFA for a user, that user must register their device again.
Enable or Disable MFA for One ShipHero User
- Go to the Users page and select the user's name to open their settings.
- Toggle Multi-Factor Authentication On to enable it, or Off to disable it.
- Select Save.
Enable MFA for Multiple ShipHero Users
- Go to the Users page and check each user you want to update.
- Select Enable MFA.
- Select Enable to confirm.
How to Register a Device for ShipHero MFA
After MFA is turned on, ShipHero asks the user to register a device the next time they log in. The registered device supplies the verification code. It does not need to be the same device the user logs in to ShipHero with.
- Log in to ShipHero with your username and password.
- Scan the QR code with the device you want to use for MFA.
- Enter the code from your authenticator app and select Continue.
- Save the recovery code ShipHero displays somewhere secure. You need it to log in if you lose access to your authentication device.
- Check I have safely recorded this code to finish logging in.
Staying Signed In to ShipHero: Remember This Device
The Remember this device for 30 days option keeps you signed in to ShipHero on that device for 30 days. ShipHero does not ask you to log in again on that device during that time. The option is on both the web and mobile sign-in screens.