FAQ: Two-Factor Authentication (2FA)

Answers to FAQ

Two-factor authentication (2FA) offers a high level of security and reliability. Once set up, the authenticator app does not rely on network or phone connections. Customers can use their preferred authenticator app with the Merchant panel log in. It is immune to attacks such as SIM card hijacking or cloning. 

Learn what to do in the following situations:

"Invalid session" notification on login page
If the login page remains open for more than 15 minutes, you will receive an "Invalid session" notification. To fix this, simply refresh the login page and try again.
Choosing authentication app for two-factor authentication (2FA)

We recommend one of these free authenticator apps for Two-Factor Authentication (2FA) in the Merchant panel: Google Authenticator, Microsoft Authenticator or FreeOTP.

Note: There can be other authenticator apps that have a fee attached to them, please double check which one you download before using it. 

Google Authenticator Microsoft Authenticator FreeOTP

Click the link to download the app or learn more about the app.

Use Microsoft Authenticator without Microsoft account
If you want to use the Microsoft Authentication without a Microsoft account, click “Scan a QR Code”. If needed, see detailed instructions to enable two-factor authentication (2FA)

Screenshot 2025-02-05 at 16.05.38.png

Use Google Authenticator without Google account
If you want to use Google Authenticator without a Google account, click “Use Authenticator without an account”. If needed, see detailed instructions to enable two-factor authentication (2FA)

Screenshot 2025-02-05 at 16.12.24.png

Use another authentication method

Only an authentication app can be used for two-factor authentication (2FA) with the Merchant panel. Bank credentials or SMS verification are not supported.

QR code not showing on login page

If two-factor authentication is already set up, the QR code won’t appear on the login page. To restore it, reset your two-factor authentication.

Tip: No reset needed if you already have an authentication app—just use the code from your app to log in!

Multiple users share a single Paytrail merchant account

For security purposes, this is not recommended. When each user has their own user account for the Merchant panel, it significantly enhances security and allows each user to be assigned different levels of rights/roles. See instructions on creating users.

However if this is not possible, all users must enable multi-factor authentication using the same QR code. For the same account, you can enable two-factor authentication (2FA) on multiple devices by using the same QR code.

Reset two-factor authentication (2FA)

Resetting two-factor authentication (2FA) restores the setup process, allowing you to rescan the QR code. This may be needed if your device with your authentication app is unavailable and changing code required to log in to the Merchant panel is no longer accessible.

Steps to reset 2FA for other users in the Merchant panel

A user with the "Manage users" role can reset 2FA for other users in the Merchant panel by following these steps:

  1. In the Merchant panel, select "Users" from the menu on the left.
  2. Select the desired user to open their profile details.
  3. Click "Reset 2FA" at the bottom of the screen.
No one with the Manage users role is available.

If there is no one in your company with the Manage users role who can reset your two-factor authentication, please contact our customer service at support@paytrail.com or by phone at +358 20 718 1820 (Monday-Friday from 8-22 and weekends from 10-18).

Error message after scanning the QR code with authenticator app

Sometimes reading a QR code directly with a device might not work. In this situation, you can try zooming in on the QR code so that the authenticator (2FA) app can read the code correctly.

Note: Please make sure you are scan the QR code from the authenticator app and not using your phone's camera.

Each app provides a user guide where you find help when facing app related challenges:

"Invalid code" error on Merchant panel user activation page

First, please ensure that you used the authentication app to first scan the QR code from the Merchant panel "Username activation" page. Once the QR code has been scanned, enter the six-digit, one-time code displayed in the authenticator app into the field on the login page. 

Note: Do not use the long code visible on the the Merchant panel page.
2FA QR code number wrong.png

If you get an error after entering the code on the Merchant panel page, try one of these options:

Wait Reinstall Download different app Check phone settings

Wait for the authenticator app to refresh and display new code

The authenticator app will display the code for a short period of time (usually every 30 seconds). If the code is not entered on the Merchant panel user activation page in that time frame, the authenticator app refreshes and displays a new code. Make sure the code is entered within this time period.

Device changed or unavailable

If the device you use for two-factor authentication (2FA) has changed or is unavailable, use these reset 2FA instructions.

Was this article helpful?
0 out of 1 found this helpful