Two-factor authentication (2FA) helps to enforce information security in your admin. Once it's enabled, the system will send a verification code to the account owner via email during the login process. The account owner must put the correct email address, password along with the correct verification code within a limited time.
Merchants can set up this feature for account owners and the Admin separately:
- Enable two-factor authentication (only accesible to store owner)
- Google Authenticator verification
- Email verification
- Customizable authentication settings for staff members
- Notes
1. Eable two-factor authentication (only accessible to store owner)
Step 1
In the SHOPLINE Admin, go to [Settings] > [Permission & Security]. Click on the tab “Security Setting”.
*Note: This feature is only available to the store owner.
Step 2
Find the "Login Management" section, and switch on the toggle for "Enable two-factor authentication for login”, then click Update.
*Notes:
- A ntoice window will pop up. Please click OK after reading the notice.
- Once the feature is enalbled, All staff members, including the store owner, will be logged out from the online store admin in 15 minutes and will need to perform 2FA during the next login.
-
Using the following systems will not be logged out:
- POS (must be iOS v1.59.0 or Android v1.31.0 or later versions )
- Admin app
- Smart OMO app
Step 3
There are two authentication methods:Google Authenticator verification and Email verification. Please select a method, scroll to the bottom, and click Upate to save the changes.
Google Authenticator verification
2. Google Authenticator verification
Step 1
On your mobile phone, open App Store or Google Play, search and install Google Authenticator. Once installed, click Already installed, next step.
Step 2
Go to Google Authenticator. Select "Scan a QR code" or "Enter a setup key" to obtain the authentication code. Then, click Next step: Enter code.
Scan a QR code/ Enter a setup key
In Google Authenticator, click the "+" button on the bottom right corner. Select Scan a QR code or Enter a setup key.
QR Code | 設定金鑰 |
Step 3
Enter the 6-digit verification code from Google Authenticator, and click CONFIRM BINDING.
*Note: On Google Authenticator, a timer icon will be displayed next to the verification code to indicate the remaining time. Oncee the time is up, there will be a new verification code automatically.
3. Email verification
Go to the email inbox you have registered with. Find the email that includes the 6-digit verrfication code. Enter the code and click SUMBIT.
Verification code email
The verification code expires in 5 minutes. If the code expires, please click RESENT on the login page.
4. Customizable authentication settings for staff members
If the store owner disabled the once-enabled 2FA, each staff memeber still need to undergo 2FA during login. To completely disable 2FA, staff members can customize the settings in [My Prrofile].
*Note: If two-factor authentication is enabled, staff members will NOT be able to customize the settings.
Step 1
In SHOPLINE Admin, go to [Hello, OOO] > [My Profile].
Step 2
Check the box for Enable OTP (You will get the OTP at this email address whenever you want to log into the Admin) and click SAVE. You will be redirected back to the login page. Please log in again with the correct email and password.
5. Notes
- If you manage multiple stores, the system will use the highest-security verification method for your login authentication.
Security levels from highest to lowest: Google Authenticator verification > Email verification > No verification.
Example
A is a staff member for the following stores. The system determines the highest
security level and selects it as A's login verification method.
Therefore, A's login verification method is "Google Authenticator verification".Store Login verification method Flower shop Email verification Bookstore Google Authenticator verification Shoe store Email verification Clothing store No verification
- If you have enabled Google Authenticator and would like to change to "Email verification" or "No verification", please contact our Online Merchant Sucess Team.
- If a staff member has enabled Google Authenticator yet needs to unbind it, please contact the store owner. If the store owner needs to unbind Google Authenticator, please contact our Online Merchant Sucess Team.
Unbind a staff member's Google Authenticator
1. Store owner goes to Admin > [Settings] > [Permission & Security] > Edit.
2. Find the "Enabled Google Authenticator" field.
3. Click Unbind.
Read more
SHOPLINE Admin Data Security Features
Comments