Two-step authentication recovery codes

When you set up two-step authentication, you can save 10 recovery codes and store them in a safe place. Recovery codes let you access your Shopify admin if any other authentication method isn't available. For example, if you don't have access to your mobile device, then you can use one of your recovery codes to log in to your account.

Store your recovery codes in multiple ways, in safe and confidential places that you can access from anywhere. You can copy or download the recovery codes. In addition, you can store your recovery codes in a password manager or a cloud storage location that you can access easily, such as the following platforms:

Regenerate and save your recovery codes

If you didn't save your recovery codes when you set up your authentication method, then you can regenerate new codes at any time. You must be logged in to your Shopify account to regenerate your recovery codes. Each user on your Shopify account has a different set of codes.

Steps:

  1. From your Shopify admin, click your store name in the top bar.

  2. Click your profile, and then click Security.

  3. In the Two-step authentication section, under Recovery methods, click Regenerate codes.

  4. Your new recovery codes are displayed on-screen. They can only be viewed one time.

  5. To save a copy of your codes, do any of the following:

    • To copy and paste the recovery codes into an electronic document, click Copy codes.
    • To download the recovery codes to a .txt file on your device, click Download codes.
  6. Store your recovery codes in a safe, confidential location.

Troubleshooting two-step authentication access

Unable to access two-step authentication code

If you can't access your two-step authentication code, then use one of your previously saved recovery codes to log in. Your recovery codes were provided when you set up two-step authentication and can be downloaded as a file called shopify_recovery_codes.txt.

If your store is on the Shopify Plus plan, then your organization might have access to a self-serve two-step authentication reset. Contact your organization owner to learn more about resetting two-step authentication for your organization.