MerchantFlow Account Security Guide
Learn how MerchantFlow protects your account with email verification, two-factor authentication (2FA), backup codes, and session security.
MerchantFlow Account Security Guide
MerchantFlow account security protects your e-commerce analytics workspace through a layered approach that includes email verification, password protection, and authenticator-based two-factor authentication (2FA). These measures safeguard your financial data, integrations, and team access.
How Email Verification Works
MerchantFlow sends a verification email after signup.
Verification matters because:
- It confirms the address used for workspace ownership and notifications
- Stripe checkout requires a verified email before a payment method can be added
- It reduces the risk of abandoned or mis-addressed accounts
How Two-Factor Authentication (2FA) Works
MerchantFlow uses TOTP-style 2FA with an authenticator app (such as Google Authenticator or Authy). Codes are 6 digits and rotate every 30 seconds, and the account appears in your app under the issuer name MerchantFlow.
2FA is mandatory, not optional, for anyone who signs in with an email address and password. You are redirected to /setup-2fa and cannot continue until it is enabled:
- Workspace owners - during the onboarding steps, before onboarding can be completed
- Invited team members - before the dashboard can be opened at all
Two cases are exempt because a password-based second factor does not apply to them:
- Social sign-in (Google or Facebook) accounts with no MerchantFlow password - those accounts are secured by the provider
- The Shopify-embedded app, where Shopify has already authenticated the session
During sign-in, users with 2FA enabled are redirected to /verify-2fa.
How to Use Backup Codes
MerchantFlow issues 10 backup codes during 2FA setup for recovery purposes. Keep them in a secure place outside the workspace - a password manager is ideal.
You can regenerate them at any time from Settings > General by confirming your password. Regenerating invalidates every previously issued code.
Password Requirements
Passwords you set at signup, when accepting a team invitation, through the password reset flow, or in Settings > Security must:
- Be at least 8 characters
- Contain at least one uppercase letter
- Contain at least one lowercase letter
- Contain at least one number
- Contain at least one special character
Every one of those forms enforces all five rules. Signup and the reset form also show a strength meter under the field that ticks off the rules as you meet them, as does the password card in Settings > Security; the invitation form checks them when you submit.
If your account has no password yet
Accounts created by a Shopify App Store install start without a password - you can open the app from your Shopify admin, but you cannot sign in at app.merchantflow.ai. In that case Settings > Security shows Set a web password instead of Change Password, along with the email address you will sign in with.
Inside the Shopify admin that card does not create the password on the spot. Every Shopify staff member with app access resolves to the same MerchantFlow user, so the button reads Email me a setup link and sends a link to your account address - only someone who can read that mailbox finishes the setup. The sign-in page offers the same route. See Password Reset for the full walkthrough.
If you are already signed in on the web without a password - a Google or Facebook account, for example - the same card lets you set one directly, and Generate strong password produces a value that meets every requirement. Passwords set that way trigger a notice email to the account address, so review it if you did not expect it.
Password Management Best Practices
- Create a strong password at signup, invite acceptance, or in Settings > Security
- Use the password reset flow if you lose access
- After resetting your password, sign in again and complete 2FA verification - a reset signs you out everywhere
How to Keep Your Workspace Sessions Safe
Browser sessions last 30 days and are refreshed about once a day while you keep using MerchantFlow. There is no per-session revocation screen in the dashboard today, so if you need to end sessions on other machines, run a password reset - that revokes every existing session.
Use these practices for shared workspaces:
- Enable 2FA on every active operator account
- Remove ex-team members promptly
- Avoid sharing a single login across multiple people
- Keep the primary owner email current
Frequently Asked Questions
How do I enable two-factor authentication in MerchantFlow?
You do not have to go looking for it - MerchantFlow requires it. Owners are sent to the 2FA setup screen during onboarding, and invited team members are sent there before they can open the dashboard. You will use an authenticator app to scan a QR code and generate time-based verification codes.
What authenticator apps work with MerchantFlow?
MerchantFlow supports any TOTP-compatible authenticator app, including Google Authenticator, Authy, Microsoft Authenticator, and 1Password.
What should I do if I lose my authenticator device?
Use one of your backup codes to sign in. If you do not have backup codes available, contact [email protected] for account recovery assistance.
Does MerchantFlow support SMS-based 2FA?
MerchantFlow currently uses authenticator-app-based TOTP for 2FA. SMS-based verification is not available.
How long does a MerchantFlow browser session last?
Browser sessions expire after 30 days and are refreshed roughly once a day as you use the dashboard. Resetting your password revokes all existing sessions immediately.
How do I know if my email is verified?
If you can complete Stripe checkout and access billing features, your email is verified. If billing blocks you with a verification prompt, check your inbox for the verification email.
Related Guides
Last updated: August 31, 2026
Last updated on
MerchantFlow General Settings Guide
Every setting on the MerchantFlow General settings page explained: profile info, dashboard currency, store timezone, language, financial preferences, security, and account deletion.
Reset Your MerchantFlow Password
Step-by-step guide to reset your MerchantFlow password, recover account access, and troubleshoot common password issues with 2FA.