Skip to content

Management Account Security and Recovery ​

Management two-factor authentication protects customer-account sign-in. It does not change mailbox authentication or configure your email apps; see 2FA and email. To change your customer-account password, use the password guide.

For setup or removal while signed in, open Security in the Management Panel. On a phone or narrow window, open the navigation menu at the top left. If you cannot pass the authenticator prompt, go to lost-authenticator recovery.

A qualifying service is a service that is not cancelled, terminated, or marked as fraud. Pending and suspended services count for these account settings. See account restrictions if a control is unavailable.

Without a qualifying service, setup, verification, setup cancellation, and disabling 2FA in Security are unavailable. Password changes and the sign-in recovery flow remain available.

Finish setup before leaving

2FA becomes active when you begin setup. Have your authenticator ready, then complete verification or select Cancel before leaving the setup page. Closing the tab does not cancel setup.

Enable two-factor authentication ​

Available when the account has a qualifying service. Have an authenticator app ready before starting.

  1. Open Security.
  2. Under Two-Factor Authentication, read the setup notice.
  3. Select Enable Two-Factor Authentication only when ready to finish setup now.
  4. Stay on the setup page. Scan the QR code with your authenticator app, or enter the displayed secret key manually into the app.
  5. Save the secret key securely so you can restore access to the authenticator entry if needed.
  6. Select the checkbox confirming you have saved the key.
  7. Enter the current six-digit Verification Code from the authenticator app.
  8. Select Complete Setup.
  9. Confirm that the page reports two-factor authentication is enabled.

Subsequent sign-ins require your password and an authenticator code.

Cancel unfinished two-factor setup ​

  1. While the QR code and secret key are displayed, select Cancel if you cannot complete setup.
  2. Confirm that the setup form closes and the page shows 2FA as disabled.

Closing the tab is not the same as cancelling setup. If you have already lost access, use lost-authenticator recovery.

Disable two-factor authentication ​

Available while signed in, with a qualifying service.

  1. Open Security.
  2. Under the enabled Two-Factor Authentication section, enter your account Password.
  3. Select Disable Two-Factor Authentication.
  4. Check for confirmation that two-factor authentication has been disabled.

Future Management sign-ins no longer request the authenticator code. If you cannot sign in, follow lost-authenticator recovery instead.

Recover access after losing your authenticator ​

You must first know your customer-account password. If necessary, reset the password before following these steps.

  1. Sign in with your account email and password.
  2. On Verify your sign-in, find Lost access to your authenticator app?.
  3. Select Lost Authenticator if offered.
  4. Follow the Stripe-hosted identity-verification instructions using your government-issued ID and any requested camera checks.
  5. Return to Management and read the result.

If verification is accepted for account recovery, 2FA is removed and sign-in completes. Return to Security to set up your replacement authenticator when eligible.

If the result says a support ticket was created because the verified name does not match the account, wait for follow-up at your account email. If the page offers Try Again, retry after addressing the stated issue. Request Manual Review is available on the retry screen when you need assistance.

If the sign-in page offers Request 2FA Removal instead of Lost Authenticator, select it and confirm the request. Support follows up at your account email to verify your identity. A request for review is not immediate approval or immediate removal of 2FA.

Who needs a footer?