- Short answer
- Not by default — the choice is yours, unless you use Shopify Payments or an admin sets a secure sign-in method as required for you.
- If you use Shopify Payments
- Required to use it, and Shopify says payouts might be placed on hold until it is activated
- When Shopify itself asks
- You're prompted at the next login and must finish setup before you can continue to the Shopify admin
- Forcing it on your team
- Per user from Settings > Users; only Plus can do everyone at once; flipping it logs that user out
- Methods that count
- SMS, an authenticator app, a built-in authenticator, a security key, and Shopify mobile prompts as a backup
- If you lose your method
- 10 recovery codes are offered at setup; without them, recovery means verifying your identity
- What Shopify doesn't say
- Nothing on the five method pages we read ties a two-step method to a particular plan
When is two-step authentication actually required?
Shopify answers this in two places, and the two answers look opposite. Its organization-security page says the decision is yours; its sign-in page and its Shopify Payments pages say the platform requires it. Both are true — they describe different merchants.
Three situations decide which answer is yours:
- Nobody is enforcing it. It stays optional. Where an organization sets no requirement, the choice is left up to the user.
- You take payments through Shopify Payments. Then it is not optional at all, and this is the branch merchants miss.
- Someone with admin access has set it to required for you. Shopify documents that switch on each user's own profile under Settings > Users. Requiring it of every user at once is the version only a Plus organization has.
The second branch lives on a different page from the one that says the choice is yours, which is why the two never meet:
To use Shopify Payments to accept payments requires you to activate two-step authentication on your Shopify account.
The payments side of the documentation puts it in its own words — to use Shopify Payments, you must secure your account by setting up two-step authentication. And the sentence quoted above turns up word for word on Shopify's account-security best practices page. So for a merchant taking card payments through Shopify's own processor, the answer is yes — even while Shopify's organization-security page says the choice belongs to the user.
What happens if you don't turn it on?
Where nobody requires it, nothing happens — the two consequences below belong to the branches that do, and they land at two different moments. The first is access, and it is not a reminder you can dismiss: when the platform is the one asking, Shopify prompts you to set up a method the next time you log in, and you need to finish the setup before you can continue to the Shopify admin.
The second is money, and merchants tend to meet it late. Shopify's Shopify Payments account-setup page says payouts might be placed on hold until two-step authentication is activated on the store — its word is might, and it does not say when, or how often that happens in practice. Read the two together and two-step authentication is a condition of using Shopify Payments, and until it is switched on Shopify says payouts might be held — which is why it is worth doing before a payout cycle rather than during one. The product itself is covered in our guide to how Shopify Payments works.
One nearby prompt is easy to misread as two-step authentication and is not: Shopify says that if you haven't logged in for three months or more, you need to confirm your identity as part of the login process. Shopify states that requirement without any reference to two-step authentication — it is a separate check, not the two-step prompt.
Can you require two-step authentication for your staff?
For everyone at once, only on Plus. For one person at a time, Shopify documents where the switch lives but never which plans have it. Shopify's organization-security page states that requiring a secure sign-in method is available only for organizations on the Shopify Plus plan, and its user-security page says the same from the other side.
Switching a user to required signs that user out. Shopify documents that changing the two-step authentication setting from not required to required logs the user out of Shopify, and its own advice is to check first that the person is not in the middle of a task. The warning is written per user, so it holds whether you flip one profile or, on Plus, everyone at once.
The per-user setting sits on each user's own profile. To reach it, from your Shopify admin you go to Settings > Users, open the person, and set whether a secure sign-in method is required for them. The plan note on that page covers only the all-users version, and Shopify states no plan requirement for the per-user one — nor that every plan has it. What Plus buys here is reach — one switch that lands on every user in the organization at once.
Which sign-in methods does Shopify count?
Shopify has a wider term for this — secure sign-in — and its page on that says secure sign-in methods can include two-step authentication and passkeys — inclusive wording rather than a closed list.
Shopify's two-step page documents four methods, each with its own help page, and a fifth that exists only as a backup:
- A code by SMS. You set up your mobile device to receive a one-time six-digit code.
- An authenticator app. You install the app first; it then generates the codes.
- A built-in authenticator. An authenticator built into your device that is compatible with the WebAuthn standard acts as the second factor.
- A security key. This one carries a precondition — you need to migrate your Shopify accounts to use your Shopify ID — which is a setup step, not a plan tier.
- Shopify mobile prompts. The Shopify app on your phone confirms the login. This one carries a hard limit the other four do not: Shopify says mobile prompts can only be used as a backup two-step authentication method, so it is the second thing you add, never the one you lean on.
No plan gate appears on the method pages we read: no page we read in August 2026 — the SMS, authenticator-app, built-in-authenticator, security-key and mobile-prompts pages — ties a particular method to a particular plan.
One thing this list is not about is your customers: passkeys turn up on the shopper side too, where new customer accounts sign someone in with a one-time 6-digit verification code, Shop credentials or a saved passkey. That is a different surface from admin sign-in, and it is covered in our guide to the customer accounts migration.
What if you lose access to your authentication method?
Save the 10 recovery codes when you set it up. Shopify offers them at that step for exactly this case: they let you access your Shopify admin if any other authentication method isn't available, and it tells you to store them in a safe place. They are emergency access rather than an extra sign-in method — the wording Shopify uses is for when nothing else is available, which is also why they are worth storing away from the phone that holds your authenticator app.
Lose both and the route is slower, not closed. Shopify says that if you lose access to both your authentication method and your recovery codes, you can recover your account by verifying your identity.
For staff, a reset carries two conditions, and the first one is Plus. Shopify lists "Reset two-step authentication for users" among its advanced security features, and those are available only for organizations on the Shopify Plus plan. The second condition is the email domain: two-step authentication can be reset only for staff members whose email address uses a domain you have verified. Everyone else — on Plus or not — completes the account recovery process for their own Shopify ID. Saving the 10 codes at setup is the cheapest thing on this page.
This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.
Editorial Policy