SoftwareSilo Customer TFA adds a second verification step to Magento storefront customer accounts. After Magento accepts the email address and password, an enrolled customer enters a current six-digit code from an authenticator app or one unused recovery code.
Choose an optional or mandatory policy: With optional TFA, customers decide when to enroll from My Account. With mandatory TFA, customers who have not enrolled are guided through setup during sign-in before they can use protected account pages.
Works with standard authenticator apps: Enrollment uses a QR code and a manual secret for time-based one-time passwords. The customer confirms setup with a current code before TFA becomes active.
Recovery without exposing the secret: The module creates a configurable number of one-time recovery codes after enrollment. Codes are shown once, stored as hashes and invalidated individually after use. Regeneration can require the customer's current TFA code or password.
Customer controls remain in My Account: An enrolled customer can review the remaining recovery-code count, regenerate codes and disable TFA when the store policy makes it optional. The original setup secret and used recovery codes are not displayed again.
Administrative support without access to private codes: A dedicated customer section shows whether TFA is enabled and lets an authorized administrator reset it. The administrator cannot view the authenticator secret or recovery-code values.
Configurable verification limits: Store settings control the issuer name, setup lifetime, recovery-code count and maximum verification attempts. Reaching the limit ends the current verification flow instead of accepting unlimited guesses.
Focused on storefront customers: The package protects Magento customer sessions. It does not replace Magento Admin TFA, send codes by email or SMS, remember trusted devices, or add customer TFA endpoints to REST and GraphQL.
- Current Version1.0.1
- Compatible with Magento 2.4.6 - 2.4.9
- Compatible with PHP 8.1 - 8.5
If your environment differs from the listed requirements, we can check compatibility in advance. Please contact us via our contact form.