Skip to main content

Overview

Secure your HitPay account by enabling 2FA to provide an additional layer of security when logging in. Follow these steps to set up 2FA:
1

Access Security Settings

Click on Security from the top-right portion of the menu as shown below.
Security Menu
2

Enable 2FA

Click on “Set up two-factor authentication”.
3

Install Authenticator App

You will need to use any authenticator app such as Google Authenticator or Microsoft Authenticator available from the Apple App Store or Google Play Store. Follow the on-screen guide to proceed.
4

Scan QR Code

Scan the Barcode generated using your chosen Authenticator App and click Continue.
5

Verify Setup

Enter the code from your Authenticator App and Click Verify.
2FA Successfully Enabled
2FA is now activated! You will be prompted to enter a 2FA code from your authenticator app every time you log in to HitPay with your password, on the web and on mobile.

Passkeys

A passkey acts as 2FA, so there is no OTP — faster sign-in. Use your fingerprint, face, or screen lock on the web dashboard.
Passkeys on iOS and Android are not yet available.
Passkeys on the HitPay Security page
  1. Click Security in the top-right menu, then Add passkey.
  2. Confirm with your password, or a 6-digit email code if you do not have a password.
  3. On dashboard.hit-pay.com/login, click Log in with a passkey.
You can add up to 10 Passkeys. Password login still asks for an authenticator code.

How to reset 2FA

Account owners

Sign in to the web dashboard with your email and password. On the authenticator prompt, click Lost access to your authenticator? HitPay asks for a selfie check. After you submit, HitPay reviews the request within 1 business day.

Non-owners

You cannot complete the selfie reset. Clicking Lost access to your authenticator? shows Ask your account owner to reset your 2FA. If you belong to one business, it also shows the owner’s masked email. The owner, or an admin whose role is above yours, resets it from Settings → Staff: open the person’s menu, click Reset 2FA, and confirm with their authenticator or SMS code (not email 2FA). They cannot reset someone at the same role or above, or someone who owns another HitPay business.
Last modified on September 14, 2026