Two-step verification
Two-step verification adds a second step to signing in. After your password (or Google), FlowPOS asks for a 6-digit code from an authenticator app on your phone, such as Google Authenticator. Someone who learns your password still cannot get in without your phone.
Two-step verification belongs to your account, not to one business. Once it is on, it applies in every business you belong to.
If you don't see Security on your profile page, two-step verification is not yet available for your business.
Turn it on
- Open your profile and choose Security.
- Under My two-step verification, choose Set up authenticator app.
- If asked, confirm your email address first, or sign in again to confirm it's you.
- In your authenticator app, add an account and scan the QR code. If you can't scan it, type the setup key shown below the code.
- Enter the 6-digit code your app shows, give the authenticator a name (for example, "My phone"), and choose Turn on.
FlowPOS emails you whenever an authenticator is added to or removed from your account. If you get one of these emails and it wasn't you, contact support right away.
Sign in with a code
After your email and password (or Google), enter the 6-digit code from your app.
- Codes change every 30 seconds. If one is rejected, wait for the next code and try again.
- After too many wrong codes, wait a few minutes before trying again.
- If the code step takes too long, FlowPOS asks for your email and password again.
Remove your authenticator
- Open Profile → Security.
- Next to your authenticator, choose Remove, then confirm it's you.
You can't remove it while a business you belong to requires two-step verification for your role. The page names that business.
Lost or changed phone
There are no backup codes. If you lose the phone with your authenticator app, contact FlowPOS support. After checking it's really you, support removes the authenticator so you can sign in with your password and set it up again. You and the owners of your businesses are emailed when this happens.
For owners: require it for chosen roles
Owners and administrators can decide how two-step verification works in their business under Profile → Security → Business sign-in policy:
| Policy | What it means |
|---|---|
| Off | Nobody in this business is offered two-step verification. |
| Optional | Anyone can turn it on for their own account. |
| Required for selected roles | People in the roles you choose must use it after a deadline. |
When you require it, people in those roles see a reminder until the deadline (7 days by default; you can choose an earlier date). After the deadline, anyone in those roles who hasn't set it up is asked to do so before they can continue — whatever they were doing on the page is kept.
The Users page shows a 2FA column so you can see who has turned it on before the deadline.
Lowering the policy, removing a role, or moving the deadline later requires you to have signed in with your own code.
The policy does not cover the Print Bridge local password, the Print Bridge emergency token, or assistant (MCP) API keys.