Authenticator App for Paystack 2FA: Authenticator App, Backup Codes & Passkeys
paystack.com ↗A Paystack account can provide access to transactions, customers, refunds, disputes, settlements, and business payment settings.
That makes the login itself worth protecting.
Paystack supports app-based two-factor authentication (2FA) using time-based one-time passwords, or TOTP. After entering your normal login credentials, you can be asked for a six-digit code generated by your authenticator app.
Paystack also provides backup codes and passkeys, giving businesses more than one way to protect Dashboard access.
How Paystack 2FA Works
When two-factor authentication is enabled, signing in generally follows this flow:
Username + password → Authenticator code → Paystack Dashboard
The six-digit code is generated by the authenticator app linked to your Paystack user account.
Paystack describes these codes as Time-based One-time Passwords (TOTP).
Because the code is generated locally by the authenticator app, you do not normally need to wait for an SMS each time you sign in using app-based 2FA.
How to Enable 2FA on Paystack
Sign in to your Paystack Dashboard first.
Then:
- Open Settings.
- Go to the Profile tab.
- Find Two-factor authentication.
- Toggle 2FA on.
- Open your authenticator app.
- Scan the QR code displayed by Paystack.
- If scanning does not work, use the text setup code instead.
- Enter the generated six-digit TOTP into Paystack.
- Select Enable.
Once Paystack verifies the code, 2FA is active for that user account.
Add Paystack to Authenticator ℠ App
To connect Paystack to Authenticator ℠ App, begin the process from the Paystack Dashboard.
Do not create a random Paystack entry inside the authenticator first.
The correct flow is:
Paystack Settings → Enable 2FA → Paystack QR code → Authenticator ℠ App → Scan → Enter generated code
After scanning the QR code, Authenticator ℠ App can generate the temporary codes required for Paystack login.
If the QR code cannot be scanned, use the manual setup code shown by Paystack.
Paystack 2FA Is Per User, Not Per Business
This is especially important for companies with several Dashboard users.
Paystack states that 2FA works on a user basis.
That means enabling 2FA on your own profile does not automatically enable it for every other person with access to the same Paystack business.
An administrator can see which users have 2FA enabled and which do not.
For teams handling payments, transfers, refunds, or sensitive customer information, this distinction matters.
One protected administrator does not make every user account protected.
What Are Paystack Backup Codes?
When you enable Paystack 2FA, Paystack provides 10 backup codes.
These are designed for situations where you cannot access the authenticator app.
For example:
- Your phone is lost
- Your phone is damaged
- The authenticator app was removed
- You changed devices without transferring the account
- Your normal TOTP codes are temporarily unavailable
A backup code can be entered instead of the six-digit authenticator code.
Each backup code works only once.
After you use one, Paystack emails you and tells you how many codes remain. If all ten are used, you must generate a new set.
Where Should You Store Paystack Backup Codes?
Do not store the only copy on the same phone that runs your authenticator app.
That defeats much of the purpose of having a recovery method.
Better options include:
- A secure password manager
- An encrypted company secrets vault
- An approved offline backup
- Another protected recovery location
The goal is simple: if your phone disappears, your backup codes should still be accessible.
Logging In With a Paystack Backup Code
If the authenticator is unavailable:
- Enter your Paystack username and password.
- Continue to the verification screen.
- Select Use a backup code instead.
- Enter one unused backup code.
- Complete the login.
Remember that the code you used cannot be reused.
Moving Paystack 2FA to a New Phone
Changing phones is where backup codes become especially useful.
If you no longer have access to the device originally used for 2FA:
- Sign in using a backup code.
- Open your Paystack Profile settings.
- Disable the existing 2FA configuration.
- Re-enable 2FA.
- Scan the new QR code using the authenticator on your new phone.
- Confirm with the new six-digit TOTP.
This reconnects Paystack to the new authenticator device.
If you still have the old phone, it is safer to complete the migration before wiping it.
Lost Both the Authenticator and Backup Codes?
This is the difficult recovery scenario.
Paystack instructs users who no longer have their authenticator device and cannot find their backup codes to contact Paystack support so their identity can be verified before 2FA is manually reset.
That is intentionally more restrictive than simply sending a normal password-reset email.
For a payment account, bypassing the second factor should require stronger verification.
Sign In with Authenticator ℠ App & Enable 2FA for Paystack 2FA: Authenticator App, Backup Codes & Passkeys
Simply download and open the Authenticator ℠ App, find your Paystack 2FA: Authenticator App, Backup Codes & Passkeys account, and enter the current verification code when prompted. After enabling 2FA, you'll need both your password and a temporary authentication code when signing in. Click on the button below Download on the App Store or scan the QR Code.
Paystack 2FA: Authenticator App, Backup Codes & Passkeys 2FA — Frequently asked questions
- Does Paystack 2FA: Authenticator App, Backup Codes & Passkeys support an authenticator app?
- Paystack 2FA: Authenticator App, Backup Codes & Passkeys does not list authenticator-app (TOTP) support in our directory. You can still use Authenticator ℠ App for the many accounts that do support TOTP.
- Is Paystack 2FA: Authenticator App, Backup Codes & Passkeys 2FA free with Authenticator ℠ App?
- Yes. Authenticator ℠ App is free to download and use for generating Paystack 2FA: Authenticator App, Backup Codes & Passkeys verification codes, with no sign-up required.
Disclaimer
This content is for educational purposes only.
Begamob is not affiliated with or endorsed by Paystack 2FA: Authenticator App, Backup Codes & Passkeys. All trademarks and product names are the property of their respective owners and are used solely for identification purposes.