Two-factor authentication for the admin panel

A second sign-in factor for the back office: a code from an app or from e-mail. One package covers PrestaShop 1.7, 8 and 9. Cut access off remotely, and make sensitive actions ask again.

PrestaShop 1.6 PrestaShop 1.7 PrestaShop 8.x PrestaShop 9.x ionCube
Licencja: Dożywotnia dla 1 sklepu
169,00 zł netto
(207.87 zł brutto)
Natychmiastowe pobieranie
12 miesięcy wsparcia
Zwrot 14 dni

Need help?

Our team is ready to answer all your questions.

Get in touch

Admin passwords leak. The code on your phone does not

No version of PrestaShop, including 9, ships a second authentication factor for the back office. The admin panel is defended by a password alone, and passwords leak: through phishing, through an employee's infected laptop, through a breach at some other site where the same string was reused.

The Two-factor authentication module adds a second factor: a 6-digit code from an authenticator app or from e-mail. But it goes further than typical 2FA, because a PrestaShop shop is rarely taken over through a cracked password. It is taken over through a hijacked, already-open session, in which the attacker simply gives themselves a second administrator.

Module capabilities

App or e-mail, your choice

A code from Google Authenticator, Microsoft Authenticator, Authy, 1Password or Bitwarden works with no network connection. E-mail codes are simpler for non-technical staff and are the way back in when someone loses their phone. You can enable both at once.

It asks again before sensitive actions

Adding an employee, changing permissions, exporting the customer database, touching payment configuration — the module demands a code again, even in a session that has already been verified. Six ready presets, your own rules, and a "Record this page" button, because nobody knows PrestaShop page names by heart.

Cut access off immediately

A departing employee, a stolen laptop, a suspected compromise. End their sessions and revoke their trusted devices in one click, effective on their very next request. No other PrestaShop 2FA module can do this.

1.7, 8 and 9 from one package

PrestaShop 9 removed every login hook. Instead of two separate implementations, the module guards the session rather than the login event — one code path covers all three generations, from PHP 7.1 to 8.4.

You cannot lock yourself out

Three independent ways back in: e-mail codes, ten single-use recovery codes, and an emergency unlock from the command line or by a file on the server. Every unlock is written to the event log.

Log and notifications

Who, when and from which IP — pairings, good and bad codes, lockouts, revoked sessions. Plus an e-mail to the employee whenever their account is used from a new device or a new IP address.

Product Details

Data sheet

Kompatybilność
PrestaShop 1.6, PrestaShop 1.7, PrestaShop 8.x, PrestaShop 9.x
ionCube
Tak

Frequently asked questions

Does it really work on PrestaShop 9?
Yes, and that is the main reason it was built this way. PrestaShop 9 removed every login hook, so the module does not use them — every back-office session starts unverified and the gate checks it on each request. The same package covers 1.7, 8 and 9.
What if an employee loses their phone?
They have two routes: an e-mail code, if that method is enabled, or one of the ten recovery codes printed at pairing. An administrator can also reset their 2FA from the Employees tab without touching the server.
And if I lock myself out of the panel?
The unlock from the server remains: a script run from the command line, or an empty DISABLE_2FA file in the module directory that stops the gate until you remove it. That is why it is worth confirming you have FTP or SSH access before enforcing 2FA for the administrator profile.
Are the secrets safe in the database?
App secrets are encrypted with AES-256 using a key derived from the installation key, so a database copy moved to another server is useless. Recovery codes and e-mail codes are stored only as SHA-256 hashes and cannot be reconstructed.
Does the module send anything outside?
No. The QR code is rendered locally in the browser — we deliberately avoid external generators, because they would send your employee's secret to a third party. Code verification happens entirely inside the shop. The only outbound connection is to the presta4you.com licence server.
Two-factor authentication for the admin panel
Two-factor authentication for the admin panel
169,00 zł net