Two factor authentication support for admin
For security reasons it will be favorable to add native Two factor authentication support in the admin.
-
Karen Verstraten
commented
Two-factor authentication is widely regarded as a standard security measure and increasingly expected as part of a platform’s default security feature set. The absence of native 2FA can also impact software evaluation and selection processes, where security capabilities are a formal criterion. In such comparisons, Shopware may be disadvantaged or excluded due to this limitation.
-
Yves Cannazza
commented
Shopware really needs 2FA for admin accounts by default.
It’s 2025, and relying only on a password to protect the backend feels outdated. The admin panel gives full access to orders, payments, and customer data — that should never be just one step away.Other platforms like Shopify, WordPress, and Magento have built-in 2FA already. In Shopware, you still need plugins or workarounds, which is frustrating.
A simple TOTP setup (Google Authenticator, Authy, Microsoft Authenticator) with backup codes would already go a long way. Ideally, shop owners could make 2FA mandatory for all admin users.
👉 Security should be a core feature, not an optional add-on.