Enhanced Admin Security: Two-Factor Authentication

  • Popularity Score 483 Popularity Score

    Popularity ScoreReferrals to Site/Downloads

    0 0 1+ 1+ 250+ 250+ 1000+ 1000+ 10000+ 10000+

  • Select Technology Partner
Protect your Magento backend against unauthorized logins and fraudsters today!
Compatible with:
This extension is currently unavailable on Magento Connect. Please contact the developer.

You will be re-directed to the developer's website to complete your purchase.

You must be registered and logged in to get extension key.
In order to get this extension, you must be logged in to the Magento Community. Click here to login or register.

Magento Connect 2.0

Magento Connect 2.0

Previous Next

Enhanced Admin Security: Two-Factor Authentication

NOTICE: This extension is available for Magento 1 and Magento 2. Please check our store for more details.

Protect your Magento backend against unauthorized logins and fraudsters today! Because passwords just aren't enough.

Fearing someone could log into your Magento store to download all your orders, customers and other sensitive data? Fearing hackers and the consequences after getting hacked? Fear no more!

Using the Two-Factor Authentication extension by XTENTO, additional security information will be required when logging into the Magento backend. Besides the username and the password, a so called security code (see screenshot below) will be required to log in. The security code gets generated by your smartphone (the second factor). Each security code can be used once only and is valid for 30 seconds only.

Just turn on your smartphone - open the Authenticator application - and you'll immediately see the security code required to log in, valid for the next 30 seconds only. It's really easy, but the increase in security is immense.

As long as you've got your phone, this will ensure only YOU are able to login, and nobody else. No other person is able to generate the security code as it's generated using a unique secret key only known to your phone. You can't log in if you don't have the security code. You can't log in if you don't have the password. You always need the password and the security code to log in. This makes it almost impossible for hackers to log into your Magento backend.

Setting up Two-Factor Authentication for an adminstrator in Magento is easy: Just go to the Users section in the Magento backend, click Create secret key and scan the barcode using the Authenticator application. That's it! Your account is now protected against unauthorized logins.

Get the Two-Factor Authentication extension now to protect against today's threats without the hassle and cost of yesterday's technology.

More Information

This extension is compatible with every iPhone (iOS 3.1+), iPad, iPod touch, Android (1.5+) and BlackBerry (OS 4.5-6.0) smartphone. The extension uses the free open-source Google Authenticator application to generate the security code required to log in.

Before your purchase, please make sure your device is able to run the Authenticator application.

Android: Open the Android Market and search for Google Authenticator
iPhone/iPad/iTouch: Visit the App Store and search for Google Authenticator
BlackBerry: Visit http://m.google.com/authenticator on your BlackBerry


Magento Backend Login Backend Login

iPhone Application (Screen 1: Security code generation; Screen 2 & 3: Setting up the code, required once only)
iPhone iPhone iPhone

Additional Information

The secret key will only be saved on your smartphone. Neither XTENTO nor Google will be able to recover it. The magic all happens on your device.

If you ever lose your smartphone, be sure to create a new key in the Two-Factor Authentication section under 'Users' in Magento so no one is able to log in using your smartphone.

This extension does not guarantee a 100% protection against hackers. If someone hacks your FTP server, they will be able to disable the security code login, but if that ever happens, they'd be able to download your database anyways without Magento backend access.


Please visit our store for more information about this extension. Be sure to check out the excellent reviews as well!

If you have any questions regarding this extension, please do not hesitate to contact us. We'll be happy to help!

Purchase this extension

Click here to purchase this extension. You will be redirected to our store.

Magento Version Compatibility Chart

Compatibility Chart

XTENTO - Magento Bronze Industry Partner

XTENTO Guarantee Partner Badge
M1 Extension Versions

Xtento_TwoFactorAuth 1.0.8

2016-08-11 11:23:23
  • Version number: 1.0.8
  • Stability: Stable
  • Compatibility: 1.4,, 1.4.2, 1.5, 1.6, 1.6.1,, 1.7, 1.8,, 1.8.1, 1.9,, 1.9.1,, 1.9.2,, 1.10, 1.11, 1.11.1, 1.12, 1.13, 1.13.1, 1.14, 1.14.1, 1.14.2


===== 1.0.0 =====
* Initial stable release


===== 1.0.4 =====
* Fixed an issue where the "TFA not required for certain IP" feature didn't work if the server is behind a reverse/caching proxy.

===== 1.0.5 =====
! Added compatibility for Magento CE / EE

===== 1.0.6 =====
* Fixed adminhtml controller that didn't work in some environments and led to "code is wrong" always when attempting to enable TFA.

===== 1.0.7 =====
* Fixed a bug caused by Magento patch SUPEE-6285 that lead to "Access Denied" screens for admins that don't have full access.

===== 1.0.8 =====
+ Added ability to send the admin an email containing the QR code after setting up TFA for a new admin


Hi, once we purchase the extension, how long can we get updates as magento CE updates? Thank you.
Asked by: OnuR
Thanks for your question! Your purchase includes 6 months of support and updates. After the first 6 months (for example 2 years later) you can then renew your support and update period for another 6 months. The cost is 50% of the extension price. Just let us know if there's anything else. Best regards Sebastian @ XTENTO
Answered by: XTENTO
Date published: 2015-12-26
  • y_2017, m_2, d_21, h_2CST
  • bvseo_bulk, prod_bvqa, vn_bulk_0.0
  • cp_1, bvpage1
  • co_hasquestionsanswers, tq_1
  • loc_en_US, sid_11592, prod, sort_[SortEntry(order=LOCALE, direction=DESCENDING), SortEntry(order=FEATURED, direction=DESCENDING), SortEntry(order=NUM_ANSWERS, direction=DESCENDING)]
  • clientName_magento
Get Help

Support for This Extension

The best place to start if you need help with a specific extension is to contact the developer. All Magento developers have both a contact email and a support email listed.

Magento Platform Support

If you need support for a Magento platform, there are different options for support depending on which Magento platform you are using. Below are links for specific platforms.


About the Developer

This extension was developed by and is supported by XTENTO

Enhanced Admin Security: Two-Factor Authentication is rated 5.0 out of 5 by 2.
Rated 5 out of 5 by from Easy to use and install Following instructions, install and use it without any problem.
Date published: 2016-12-09
Rated 5 out of 5 by from Top Quality Module adds significant security benefit Excellent module from Xtento - well written using Magento best practices (observer-based, non-invasive) and "just works". Very easy process to link with Google Authenticator. Highly recommended.
Date published: 2013-07-18
  • y_2017, m_2, d_21, h_4
  • bvseo_bulk, prod_bvrr, vn_bulk_0.0
  • cp_1, bvpage1
  • co_hasreviews, tv_0, tr_2
  • loc_en_US, sid_11592, prod, sort_[SortEntry(order=FEATURED, direction=DESCENDING), SortEntry(order=SUBMISSION_TIME, direction=DESCENDING)]
  • clientName_magento

In order to upload extension, you must be logged in to the Magento Community. Click here to login or register.



* Required Fields

Close window

Forgot Your Password?

Please enter your email below and we'll send you a new password.

* Required Fields

Close window


To upload extension you must be logged in.

* Required Fields

Close window

You are using an outdated browser

We built Magento Connect using the latest techniques and technologies.
This makes Magento Connect faster and easier to use.
Unfortunately, your browser doesn't support those technologies.
Use the links below to download a new browser or upgrade your existing browser.