Settings & Configuration

Settings & Configuration | Two-Factor Authentication & Passkeys

Secure your account properly: passkeys for one-touch sign-in, authenticator-app 2FA, and the recovery codes that save you when devices don't.

2 min read3viewsUpdated 27 August 2026Orbit Commerce

Your dashboard holds your money and your customers' data — the password alone isn't the right level of protection. Settings → Security has the three layers worth turning on.

Passkeys

The best option: sign in with your device's fingerprint, face or PIN. Phishing-proof by design (there is no code to type for an attacker to steal) and faster than any password. Add a passkey on every device you use — a passkey created on your phone isn't automatically on your laptop.

Authenticator app (TOTP)

The classic: scan the QR code with an authenticator app and enter the six-digit code at each sign-in. Works with any standard app. New accounts are gently pushed toward enrolling — do it early rather than at the nag's third appearance.

SMS codes

Better than nothing, weaker than the others (SIM-swap is a real attack). Fine as a backup second factor alongside a passkey.

Recovery codes — do not skip this

At 2FA setup you get one-time recovery codes. Save them somewhere that isn't the phone itself. They are the only self-service way back in when a phone is lost, stolen or drowned (see Troubleshooting | Can't Log In / 2FA Issues).

Tips

  • Every team member should enrol their own factors — shared logins defeat the entire point (see Settings | Team Roles & Permissions).

Was this helpful?

0 people found this helpful

Keep reading

Related articles