Articles in this section

How to Manage Multi-Factor Authentication (MFA) for Users

Multi-factor authentication (MFA), also called two-factor authentication (2FA), protects a ShipHero user's login by asking for a verification code from an authenticator app in addition to their password. Admins can turn MFA on or off for one user at a time, or turn it on for several users at once from the Users page.

Before You Begin

  • Required user role permission: Only users with the Admin role or the Edit Users permission can enable or disable MFA, for themselves or for other users.
  • Authenticator app required: ShipHero does not support MFA by email. Each user needs an authenticator app, such as Google Authenticator, Microsoft Authenticator, or the Passwords app on iPhone.
  • Users with API tokens: Enabling MFA for a regular user stops that user's API tokens from working. To keep API access, leave MFA off for that user, or use a developer user instead. See How to Obtain API Access and Refresh Tokens.

Table of Contents

How MFA Works in ShipHero

ShipHero MFA is adaptive. A user with MFA turned on is only asked for a code when a login looks suspicious, such as a sign-in from a new device or an unusual location.

  • Refunds: MFA is also required for sensitive actions. Issuing a refund triggers an MFA prompt on the first refund of each day.
  • API tokens: A regular user with MFA turned on cannot use their API tokens. Use a developer user for API access instead.

How to Enable or Disable MFA for ShipHero Users

MFA is set on each user's profile. Change it for one user from their profile, or enable it for several users at once from the Users page.

When you disable and then re-enable MFA for a user, that user must register their device again.

Enable or Disable MFA for One ShipHero User

  1. Go to the Users page and select the user's name to open their settings.
  2. Toggle Multi-Factor Authentication On to enable it, or Off to disable it.
  3. Select Save.
User settings in the ShipHero Web Dashboard showing the Multi-Factor Authentication toggle

Enable MFA for Multiple ShipHero Users

  1. Go to the Users page and check each user you want to update.
  2. Select Enable MFA.
  3. Select Enable to confirm.
Users page in the ShipHero Web Dashboard with several users checked and the Enable MFA button

How to Register a Device for ShipHero MFA

After MFA is turned on, ShipHero asks the user to register a device the next time they log in. The registered device supplies the verification code. It does not need to be the same device the user logs in to ShipHero with.

  1. Log in to ShipHero with your username and password.
  2. Scan the QR code with the device you want to use for MFA.
  3. Enter the code from your authenticator app and select Continue.
  4. Save the recovery code ShipHero displays somewhere secure. You need it to log in if you lose access to your authentication device.
  5. Check I have safely recorded this code to finish logging in.
Scan QR Code Enter MFA Code
ShipHero MFA setup screen showing a QR code to scan with an authenticator app
ShipHero MFA screen with a field for the authenticator app code and the Continue button

Staying Signed In to ShipHero: Remember This Device

The Remember this device for 30 days option keeps you signed in to ShipHero on that device for 30 days. ShipHero does not ask you to log in again on that device during that time. The option is on both the web and mobile sign-in screens.

ShipHero sign-in screen with the Remember this device for 30 days checkbox

More Resources

  • ShipHero Public API

    Connect your tools and AI agents directly to ShipHero with the Public API. Build powerful integrations, automate workflows, and tap into real-time data using the AI tools you prefer, with the option for secure, read-only access for AI-driven insights without added risk.

  • ShipHero Academy

    Explore ShipHero Academy for certifications, deep-dive training, and expert-led courses on WMS and fulfillment. Build your expertise and help your team operate at a higher level.

  • Change Log

    Stay up to date with the latest improvements across ShipHero. The Change Log gives you a clear view of new features, enhancements, and fixes as they roll out—so you always know what’s new and what’s better.