# 2FA Google Authenticator for PrestaShop

> Enable two-factor authentication (2FA) on the PrestaShop 8 & 9 back office with any TOTP app: Google Authenticator, Authy, 1Password, Microsoft Authenticator. Recovery codes, brute-force protection, multistore.

- Page: <https://www.datafirefly.com/en/product/2fa-google-authenticator-prestashop/>
- Language: en
- Last updated: 2026-09-08
- Platform: PrestaShop
- Category: Security & Protection
- SKU: DF-2FA-DE
- Price: 80.00 EUR
- Other languages: [fr](https://www.datafirefly.com/product/2fa-google-authentificator-pour-prestashop/index.md), [es](https://www.datafirefly.com/es/producto/2fa-google-authenticator-prestashop/index.md), [de](https://www.datafirefly.com/de/produkt/2fa-google-authentificator-fuer-prestashop/index.md), [it](https://www.datafirefly.com/it/product/2fa-google-authentificator-per-prestashop/index.md), [pl](https://www.datafirefly.com/pl/produkt/2fa-google-authenticator-dla-prestashop/index.md), [nl](https://www.datafirefly.com/nl/product/2fa-google-authentificator-pour-prestashop/index.md), [pt](https://www.datafirefly.com/pt/produto/2fa-google-authenticator-prestashop/index.md)
- Index: <https://www.datafirefly.com/en/product/llms.txt>

### Two-factor authentication (2FA) for the PrestaShop 8 & 9 back office

The PrestaShop back office is the number one attack target on your store. A compromised admin password means access to your orders, your customers, your source code. **2FA Google Authenticator** adds a second security layer: on top of the password, every admin login requires a 6-digit code generated by a TOTP app on the employee's phone.

#### Compatible with PrestaShop 8 and PrestaShop 9

The module runs natively on PrestaShop 8.0 to 8.2 and on PrestaShop 9, including the new Symfony login page of the PS9 back office. One single module version, no version-specific setup.

#### Works with every standard TOTP app

The module follows the **RFC 6238 (TOTP)** standard and works with:

- Google Authenticator (iOS, Android)
- Microsoft Authenticator
- Authy
- 1Password (built into the password manager)
- Bitwarden Authenticator
- FreeOTP
- And any other standard TOTP app

#### Global or individual activation

2FA can be made mandatory for all employees (forced mode) or left as opt-in: each employee enables their own 2FA from their user menu or from the reminder banner shown in the back office. Configuration from Modules → 2FA Google Authenticator.

#### 2-minute setup on the employee side

On first login after activation, the employee scans a QR code with their TOTP app, enters the generated code to confirm pairing, and that's it. Subsequent logins simply ask for the 6-digit code after the password. The QR code is generated locally in the browser — no calls to any external service.

#### Recovery codes

During pairing, 8 single-use recovery codes are generated and shown to the employee. Keep them somewhere safe (password manager, paper in a safe). If the phone is lost or stolen, one of these codes allows logging in and resetting the pairing. Codes are stored as SHA-256 hashes: they are never readable in the database.

#### Super Admin reset

If an employee loses both their phone and their recovery codes, a Super Admin can reset their 2FA in one click from the module configuration page. The next login will prompt the initial pairing again.

#### Brute-force protection

After 5 consecutive invalid codes, 2FA verification for the account is locked for 15 minutes. An attacker cannot enumerate the 6-digit codes, even with automated attempts.

#### Technical specifications

- **RFC 6238 (TOTP)** standard, 30-second window, 6 digits
- TOTP secret encrypted with AES-256 in the database
- Recovery codes hashed with SHA-256
- 15-minute lockout after 5 consecutive failures
- Global mandatory activation or per-employee opt-in
- 8 single-use recovery codes
- Super Admin reset
- QR code generated locally — no external dependency
- **Multistore** compatible
- PrestaShop 8.0+ and 9.x, PHP 7.4+ (8.1+ for PS9)
