Two-factor authentication
Two-factor authentication (2FA) adds a second step to signing in: after your email and password (or your Google account), you also enter a short code from an authenticator app on your phone. Even if someone learns your password, they can’t get into your store without that code. It’s optional, but recommended for the owner and anyone with access to sales and settings.
What you’ll need
Section titled “What you’ll need”An authenticator app on your phone. We use Google Authenticator as the example below because it’s free and the most common, but any of the usual apps work the same way — Authy or 1Password, for instance. The app shows a fresh 6-digit code every 30 seconds; that code is your second step.
Before you start
Section titled “Before you start”Your email must be verified. Open Account under Settings and check the Email row — it shows a VERIFIED or UNVERIFIED badge. If it’s unverified, verify your email before turning on 2FA — the setup will otherwise tell you to verify first. Once it’s on, 2FA works whichever way you sign in, with email-and-password or with Continue with Google.
Set up two-factor authentication with Google Authenticator
Section titled “Set up two-factor authentication with Google Authenticator”This is the full walk-through using Google Authenticator. If you already have an authenticator app, skip step 1.
- Install Google Authenticator on your phone. Open the App Store (iPhone) or Google Play (Android), search for Google Authenticator, and install it. Open it once — there’s nothing to set up yet.
- Start the setup in Swann Retail. Go to Settings → Account and find the Two-factor authentication card (it shows OFF). Press Set up. You may be asked to confirm it’s you first — sign in again if prompted.
- Add Swann Retail to the app. Swann Retail shows a QR code. In Google Authenticator, tap the +
button (bottom-right) and choose Scan a QR code, then point your phone’s camera at the code on your
screen.
- Can’t scan? Press Can’t scan? Enter a setup key instead under the QR code to reveal a setup key, choose Enter a setup key in the app, and type the key in. Give the account a name like Swann Retail and make sure the type is Time based.
- Enter the 6-digit code. Google Authenticator now lists a Swann Retail entry with a 6-digit code that refreshes every 30 seconds. Type the current code into the 6-digit code from your app field and press Verify and turn on.
- The card flips to ON. From now on you’ll enter a code from the app each time you sign in.
If the code is rejected, it’s usually because it just expired — wait for your app to show the next code and enter that one.
Signing in with 2FA turned on
Section titled “Signing in with 2FA turned on”Sign in with your email and password (or Google) as usual. You’ll then be asked for the 6-digit code from your authenticator app — open the app, read the current code under your Swann Retail entry, and enter it. If you see “That code didn’t match. Check your authenticator app and try again.”, make sure you’re reading the right Swann Retail entry in your app and that the latest code hasn’t just rolled over.
Which actions require two-factor authentication
Section titled “Which actions require two-factor authentication”Most of your day — ringing up sales, managing items, taking stock — never asks for an extra check. Swann Retail only steps in for a small set of sensitive actions that protect your money and your account:
| Action | Why it’s protected |
|---|---|
| Connecting or changing an integration (Loyverse, QuickBooks) | These hold the keys to another system that has your sales data. |
| Setting up a receipt-printer agent | A printer agent gets a long-lived key to your store. |
| Refunding a sale | A refund moves money back out of the till, so we confirm it’s really you. |
When one of these asks for a check and you haven’t set 2FA up — or you signed in before turning it on — you’ll see the prompt described next.
We’re still refining exactly which actions ask for a check, so this list may change as we simplify it. The actions above — the ones that protect your account, your integrations, and your money — are the ones that will keep asking.
”This action requires two-factor authentication”
Section titled “”This action requires two-factor authentication””If one of the actions above asks for a check, the prompt will be one of these cases:
| What it says | What to do |
|---|---|
| Set up two-factor authentication | You haven’t turned 2FA on yet. Use Set up two-factor authentication to go to Account, turn it on, then try the action again. |
| Sign in again to continue | You already have 2FA on, but you signed in before turning it on. Sign out and sign back in, then try again. |
| Confirm it’s you to continue | A lighter check on a sensitive action like a refund. Sign in again to verify it’s you, then try the action again. |
Turn it off
Section titled “Turn it off”Open the Two-factor authentication card on the Account page and press Remove. The card returns to OFF, and you’ll no longer be asked for a code when you sign in.
If you lose your authenticator
Section titled “If you lose your authenticator”Keep your authenticator app safe — it’s the only thing that produces your codes. If you lose your phone or can’t get a code:
- Contact support (or whoever set up your store) to have two-factor removed from your account. You can then sign in and set it up again with your new device.
- A password reset on its own won’t get you back in — the second-step code is still required after a reset. So 2FA has to be removed by support before you can sign in without your authenticator.