Magento 2 Extension Magento 2 Customer Two-Factor Authentication

Add authenticator-app verification and recovery codes to Magento 2 storefront customer accounts, with optional or mandatory enrollment.

SoftwareSilo Customer TFA adds a second verification step to Magento storefront customer accounts. After Magento accepts the email address and password, an enrolled customer enters a current six-digit code from an authenticator app or one unused recovery code.

Choose an optional or mandatory policy: With optional TFA, customers decide when to enroll from My Account. With mandatory TFA, customers who have not enrolled are guided through setup during sign-in before they can use protected account pages.

Works with standard authenticator apps: Enrollment uses a QR code and a manual secret for time-based one-time passwords. The customer confirms setup with a current code before TFA becomes active.

Recovery without exposing the secret: The module creates a configurable number of one-time recovery codes after enrollment. Codes are shown once, stored as hashes and invalidated individually after use. Regeneration can require the customer's current TFA code or password.

Customer controls remain in My Account: An enrolled customer can review the remaining recovery-code count, regenerate codes and disable TFA when the store policy makes it optional. The original setup secret and used recovery codes are not displayed again.

Administrative support without access to private codes: A dedicated customer section shows whether TFA is enabled and lets an authorized administrator reset it. The administrator cannot view the authenticator secret or recovery-code values.

Configurable verification limits: Store settings control the issuer name, setup lifetime, recovery-code count and maximum verification attempts. Reaching the limit ends the current verification flow instead of accepting unlimited guesses.

Focused on storefront customers: The package protects Magento customer sessions. It does not replace Magento Admin TFA, send codes by email or SMS, remember trusted devices, or add customer TFA endpoints to REST and GraphQL.

Authenticator-app verification

Use standard time-based six-digit codes after Magento validates the customer's password.

Optional or mandatory enrollment

Let customers opt in or require setup before they can continue into protected account pages.

One-time recovery codes

Generate a configurable set of hashed recovery codes that become invalid after use.

Self-service in My Account

Customers can enroll, view the remaining recovery-code count, regenerate codes and disable optional TFA.

Controlled admin reset

Authorized administrators can review the status and reset TFA without seeing secrets or recovery codes.

Verification attempt limits

End the current challenge after the configured number of invalid authenticator or recovery-code attempts.

Login as Customer policy

Choose whether authorized Magento Login as Customer sessions bypass the storefront TFA challenge.

  • Current Version1.0.1
  • Compatible with Magento 2.4.6 - 2.4.9
  • Compatible with PHP 8.1 - 8.5

If your environment differs from the listed requirements, we can check compatibility in advance. Please contact us via our contact form.

customer-tfa

Version 1.0.1 - 2026-08-24

Fixed
  • Ensure Magento customer login actions consistently enter the configured TFA challenge flow
  • Redirect unauthenticated visitors from protected TFA account actions without controller type errors

Version 1.0.0 - 2026-06-08

Added
  • Initial release
customer-tfa-hyva

Version 1.0.0 - 2026-08-30

Added
  • Hyva-compatible setup, verification and account-management views
  • Recovery-code download and print actions without RequireJS
  • Responsive customer account layouts for desktop and mobile storefronts
Module-Specific Questions
Which authenticator apps work with Customer TFA?

The module uses standard time-based one-time passwords. Authenticator apps that support TOTP and QR-code enrollment can be used.

Does the module send verification codes by email or SMS?

No. Verification uses an authenticator app or one of the customer's one-time recovery codes.

Can TFA be optional or mandatory?

Yes. Optional mode lets customers enroll from My Account. Mandatory mode requires setup during sign-in before protected account pages become available.

Can recovery codes be viewed again later?

No. Recovery codes are shown once after generation and stored as hashes. The account only shows how many unused codes remain.

What happens after too many incorrect codes?

The current verification flow ends after the configured maximum number of attempts. The customer must begin a new sign-in flow.

Can an administrator reset Customer TFA?

Yes, with the dedicated ACL permission. The reset removes the customer's TFA setup, but it does not reveal the secret or recovery codes.

Does this extension protect Magento Admin users?

No. It protects storefront customer accounts. Magento Admin two-factor authentication remains a separate Magento function.

Does the extension remember trusted devices or provide API endpoints?

No. It does not add trusted-device cookies or customer TFA endpoints to REST and GraphQL.

General Questions
How many Magento installations is the license valid for?

The license is valid for one Magento installation, including multi-website operation. In addition, the module may be installed on any number of development or staging servers. You can find further details in our license terms.

Is installation included in the price?

Installation and configuration are not included in the price. On request, we can support you with a smooth integration into your system.

How do I install a module?

Composer is PHP's package manager, and Magento 2 uses it to install modules and their dependencies. After purchase, the commands for your module are available under Licenses in your customer account. First add the private SoftwareSilo repository and your license token. Then install the listed package with composer require and run php bin/magento setup:upgrade and php bin/magento cache:clean.

What payment methods are available?

You can pay by credit card (Stripe) or bank transfer (prepayment). For credit card payments, the order is processed immediately and the access credentials are provided directly in a separate follow-up email.

What does the order process look like?

After credit card payment, you immediately receive access credentials to obtain the module via Composer. For bank transfer, access is granted once the invoice is paid.

I need a custom modification of the module. Is that possible?

Custom requests are no problem. We tailor our Magento 2 modules to your project and maintain a dedicated internal version so we always know exactly what runs on your system for support.

Can I install a demo version locally?

On each module detail page, you can request your own demo instance and test the module intensively for 7 days. However, we do not provide a local demo version.

Is the source code encrypted?

No, the source code of our modules is not encrypted. If you need a customization, feel free to send us a request. We will get back to you promptly with a non-binding quote.

What is the update policy and support?

You can add a support package to your order. It includes assistance as well as updates and upgrades related to the module. No continuous subscription is required.

I already have a license. How can I perform an update?

You can complete the license update here. If you have an active support package, you receive updates automatically via Composer. If your support package has expired, you can renew your license here or in your account.

I have another question — how can I contact you?

You can reach us anytime via eMail.

Magento 2 Customer Two-Factor Authentication

×

Ideal for these industries & use cases

Protect customer accounts with business data

Require a second factor for accounts that expose orders, addresses, company details or negotiated purchasing access.

Start optional and enforce later

Introduce TFA as an optional account function, then switch to mandatory enrollment after customer communication.

Give customers a recovery path

Provide one-time recovery codes and controlled regeneration when the authenticator device is unavailable.

Resolve lost-device cases in Admin

Allow a separately authorized administrator to reset TFA after checking the customer's identity through the support process.

Require TFA for every customer account

Apply mandatory enrollment when all storefront customer accounts must complete a second verification step.

Control support access through Login as Customer

Decide explicitly whether authorized support sessions bypass TFA when an administrator enters a customer account.

Try before you buy

Request a personal demo and test the module with realistic sample data in Magento Admin and the storefront. Take your time to see whether it fits your requirements and workflows.

Technical documentation

Practical Magento 2 guides, developer documentation, and API references for installation, configuration, and troubleshooting.

Go to Knowledge Base

Do you need a custom solution?

Do your requirements go beyond the capabilities of our Magento 2 modules? We develop suitable Magento 2 modules and integrations for your business processes.

Request now