Powered by Adobe Commerce 2.4.9

This extension is in our Payment category. Please remember that it is the merchant’s responsibility to ensure the proper PCI compliance level of their store, as applicable by PCI regulations. The PCI Self-Assessment is one tool you can use when evaluating Payment extensions and how they may affect your PCI compliance level. For more information on Marketplace policies, please review the Marketplace Terms & Conditions.
two-factor-authentication-240.png

2FA Authentication For Customers

PRODUCT:
0
TOTAL:

Trader Information

Back to top

Overview

Back to top

Pro Web Concepts, Inc. is a web development and digital solutions company focused on building secure, scalable, and user friendly ecommerce functionality. Built with best practices and compliances in mind, we design and build websites that are scalable, responsive, and user-friendly. Pro Web Concepts work with its client with various technology frameworks and expertise. This extension was created to help merchants strengthen storefront account security with a modern two factor authentication solution designed specifically for customer accounts.

Two Factor Authentication for Customers adds an additional layer of security to Magento storefront logins by requiring a time based one time passcode during customer sign in. After entering their username and password, customers complete login by entering a code generated in a compatible authenticator app such as Google Authenticator, Microsoft Authenticator, or Authy. Customers can enable, configure, and manage two factor authentication directly from their account dashboard, creating a simple self service experience. Built specifically for Magento 2.4+ frontend customer authentication, the extension supports native login experiences, including AJAX based checkout login flows. It is a practical solution for merchants who want to better protect customer accounts, saved addresses, order history, and other account related data on the storefront.

Account & Pricing

No separate merchant account is required to use this extension.

No account is created during extension installation.

Customers use their own compatible authenticator application on their mobile device. Supported apps include Google Authenticator, Microsoft Authenticator, Authy, and other RFC 6238 compatible authenticator applications.

No additional service fees are required to use the core functionality of this extension.

Some authenticator app providers may offer optional premium services, but those are not required to use this extension.

Authenticator app information:

• Google Authenticator: https://support.google.com/accounts/answer/1066447
• Microsoft Authenticator: https://www.microsoft.com/en-us/security/mobile-authenticator-app
• Authy: https://authy.com/

Privacy Policy

Pro Web Concepts, Inc. Privacy Policy: https://prowebconcepts.com/privacy-policy/

Support Contacts

For support related to this extension, please contact:

support@prowebconcepts.com

Features

• Adds two factor authentication to Magento storefront customer logins

• Built specifically for Magento 2.4+ frontend customer authentication

• Uses TOTP verification based on the RFC 6238 standard

• Compatible with Google Authenticator, Microsoft Authenticator, Authy, and similar authenticator apps

• Allows customers to enable and manage two factor authentication directly from their account dashboard

• Includes QR code setup for quick enrollment

• Provides manual secret entry as an alternative setup option

• Generates backup recovery codes for account access when a customer cannot access their authenticator app

• Supports trusted devices so customers can reduce repeated verification on recognized devices for a configurable number of days

• Supports Magento native customer login flows, including AJAX based checkout login

• Allows customers to regenerate backup codes from their account area

• Allows customers to revoke trusted devices from their account area

• Encrypts TOTP secrets using Magento encryption

• Stores backup codes securely as hashes instead of plaintext

• Automatically removes expired trusted device records through Magento cron

Admin Configuration

Configuration is available under Stores > Configuration > Pro Web Concepts > Frontend 2FA, with support for store scope settings.

Administrators can:

• Enable or disable the extension globally

• Define the issuer name displayed in authenticator applications

• Enable or disable trusted device functionality

• Configure trusted device duration

• Set the number of backup codes generated per customer

• Manage settings at the store view level as needed

Compatibility

Compatible with Adobe Commerce and Magento Open Source 2.4.4 and later.

Technical Specifications

Back to top

Seller profile

Pro Web Concepts, Inc

Seller contact

E-mail

Current Version

1.0.0

Adobe Commerce platform compatibility

Adobe Commerce (cloud): 2.4 (current)

Adobe Commerce (on-prem): 2.4 (current)

Magento Open Source: 2.4 (current)

Type

Stable Build

Updated

19 June, 2026

Categories

Extensions, Payments & Security

Quality Report

Back to top

Installation & Varnish Tests

Passed

Coding Standard

Passed

Plagiarism Check

Passed

Malware Check

Passed

Marketing Review

Passed

Manual Testing

Passed

All tests were conducted on the latest versions of Adobe Commerce that existed for the compatible release lines at the moment of the extension submission. Latest versions of all other software were used, as applicable.

Release Notes

Back to top

1.0.0:

  • Compatible with Adobe Commerce (cloud) : 2.4
  • Compatible with Adobe Commerce (on-prem) : 2.4
  • Compatible with Magento Open Source : 2.4
  • Stability: Stable Build
  • Description:

    Initial Release.

Support

Back to top

The best place to start if you need help with a specific extension is to contact the developer. All Adobe Commerce developers have both a contact email and a support email listed.

Contact Vendor

Q & A

Back to top

Reviews

Back to top