Two-factor authentication (2FA) — enabling it, backup codes, and disabling it
An app code as a second login factor. Some administrative operations require 2FA regardless of permissions — without it, you simply cannot perform them.
2FA is a second login factor: in addition to your password, you enter a six-digit code from an authenticator app (Google Authenticator, Authy, 1Password).
Enable it — three steps
- Confirm your current password. Setup cannot begin without it.
- Scan the QR code with an authenticator app.
- Enter the six-digit code generated by the app and confirm.
After confirmation, the system displays backup codes.
Backup codes — read this before closing the dialog
Backup codes are shown only once, at this point. You cannot view them later — you can only generate a new set.
Each code works once and replaces an app code. They are your only way back in if you lose your phone. Copy them with Copy all to clipboard and store them outside the system — in a password manager or printed out.
The security panel shows how many codes remain. When few remain, a warning suggests generating a new set. Generating new codes invalidates all old ones — the old printout stops working immediately.
Lost phone
Use a backup code instead of an app code — it works anywhere the system asks for a code, including when disabling 2FA. If you have neither your phone nor backup codes, you cannot recover the account yourself — an administrator must help.
Disable it
You need your current password and a code (from the app or a backup code). Both factors are required at once, deliberately: the password alone is not enough to disable 2FA.
Operations requiring 2FA regardless of permissions
This surprises administrators. A number of operations are protected by 2FA confirmation, and having permission is not enough — without 2FA enabled, you simply cannot perform them. These include:
- user management — creating, editing, deleting, and adding existing users,
- roles, permissions, and field permissions,
- company details — tax number, REGON, addresses, bank accounts, logo,
- user–company, user–department, and user–warehouse assignments,
- integration keys and variables (marketplaces, couriers),
- warehouse mappings and ERP price lists, plus manually triggering synchronization,
- stock and order synchronization schedules,
- replenishment, stocktaking, returns, and refund settings,
- webhook security configuration,
- customer export and bulk deletion,
- exporting orders, returns, and documents — files with customer data,
- automatic logout after inactivity,
- technical accounts — creating a program account, issuing, rotating, and revoking its tokens, and token settings,
- password changes and personal API tokens — if you have 2FA enabled.
The full current list is in the Security tab; the items above are a summary of common operations.
Practical consequence: if you are going to administer anything, enable 2FA right away. Otherwise, sooner or later, you will get stuck halfway through configuration.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo