Skip to content

WooCommerce Google Authenticator (Two Factor Authentication)

WooCommerce Google Authenticator

WooCommerce Google Authenticator adds two factor authentication to WooCommerce customer accounts. After the password, the customer enters a six digit code from the Google Authenticator app on their phone.

Customers set it up themselves from a menu on the My Account page. They scan a QR code with the app, or type the site name and secret key by hand. A code confirms the pairing and finishes enrolment. Nothing is required from you beyond turning the feature on.

Two factor is optional per customer, not forced on everyone. Accounts that have enrolled must supply a code at login. Accounts that have not can log in with a password as before. You can also exclude specific users from 2FA entirely.

What is WooCommerce Google Authenticator?

WooCommerce Google Authenticator is a WordPress plugin that adds two factor authentication (2FA) to WooCommerce customer accounts. Customers enrol from their My Account page by scanning a QR code with the Google Authenticator app. They then enter a six digit code at every login.

Why customer accounts need 2FA

Stored addresses, order history, saved payment methods, and wallet or store credit balances all sit behind a customer password. Passwords get reused across sites, and a credential dump elsewhere becomes an account takeover on your store.

A time based code changes every thirty seconds and lives on the customer’s phone. A stolen password on its own no longer opens the account.

How customers turn it on

  1. The customer opens the two factor menu on their My Account page.
  2. They scan the QR code with Google Authenticator, or enter the site name and secret key manually.
  3. They type the code shown in the app to confirm the pairing.
  4. From the next login onwards, the login form asks for the current code.

The Google Authenticator app is free on both Android and iOS, so there is nothing for customers to buy.

What you control

  • Turn 2FA on or off for the whole store.
  • Exclude specific users who should not be prompted.
  • Set the endpoint slug and menu title for the enrolment screen on the My Account page.
  • Show or hide the sidebar widgets on that menu.
  • Place the enrolment form anywhere using a shortcode.
  • Review a user list showing who has 2FA active and when they last changed it.

Who this plugin is for

Stores holding store credit, wallet balances, or subscription billing, where a compromised account has direct financial value. Membership sites and B2B portals with account-only pricing. Any store that has already dealt with a customer account takeover.

Setting up two factor authentication for WooCommerce

Configuration

General configuration page

Activate license

Enter your purchase code and email to activate the license before use.

Enable two factor authentication

Turn 2FA on or off for the store. Customers who have not enrolled keep logging in with a password, so switching it on locks nobody out.

Excluded users

Exclude named accounts that should never be asked for an authentication code.

Registration shortcode

Place the Google Authenticator enrolment form anywhere in the store with this shortcode. By default it also appears on the My Account page.

My Account menu endpoint

Set the endpoint slug for the two factor menu on the My Account page.

My Account menu endpoint title

Set the title shown on that menu.

My Account menu sidebar widgets

Show or hide the sidebar widgets on that menu.

Users: who has 2FA switched on

The users list shows every account with its two factor status, whether it is active or inactive, and when it was last changed. Use it to check adoption before you promote the feature.

Users list menu

How customers enrol in Google Authenticator

My Account menu

Customers open the two factor menu on the My Account page and pair the store with their Google Authenticator app. They scan the QR code, or type the site name and secret key by hand. Entering the current code from the app confirms the pairing.

My accounts page

The store then appears in the app as shown below, generating a fresh six digit code every thirty seconds.

Google Authenticator app page

Login form

The login form gains an authentication code field. Customers who have enrolled enter the current code from their app to sign in. Customers who have not enrolled leave it empty and log in with a password as before.

Login form

That is what makes 2FA safe to enable on a live store. A stolen password no longer opens an enrolled account, and no existing customer is locked out.

Frequently Asked Questions (FAQs)

Q1. Is two factor authentication forced on every customer?

No. Customers enrol themselves from the My Account page. Anyone who has not enrolled logs in with a password as usual, so no one is locked out when you activate the plugin.

Q2. Which authenticator apps work with it?

Any app that supports standard time based codes, including Google Authenticator on Android and iOS. Customers pair by scanning the QR code or entering the secret key manually.

Q3. Can I stop certain users from being asked for a code?

Yes. Add them to the excluded users list and the two factor prompt will not apply to their account.

Q4. Where do customers set this up?

On a menu added to the WooCommerce My Account page. You control both the endpoint slug and the title shown on that menu.

Q5. Can I show the enrolment form somewhere other than My Account?

Yes. A shortcode places the registration form on any page you choose.

Q6. Can I see which customers have 2FA switched on?

Yes. The users list shows every account, whether two factor is active, and when it was last changed.

Reviews (0)

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.