Customer 2FA
Customer 2FA
Customer account security should start as an opt-in rollout with recovery planning, not a blanket requirement.
Before inviting customers
- Confirm the store owner and staff recovery paths work.
- Decide which customer segment needs the first rollout.
- Publish plain setup and recovery expectations.
- Confirm support will not ask for recovery codes, authenticator secrets, passwords, or raw security logs.
- Test My Account, lost password, checkout login prompts, order-pay, and payment-method flows before making stronger compatibility claims.
Rollout boundaries
Customer passkeys, stricter customer enforcement, and step-up behavior are release-verified or paid capabilities. Do not promise them for every store before the current release and site-specific WooCommerce flow have been checked.
Support guidance
Support can explain where recovery starts, how to verify account ownership, and what information is safe to share. Support should not bypass ownership checks or request sensitive secrets.