Add password and TOTP multi-factor authentication to any Stencil store in minutes — no theme changes, no custom code.
No spam. Notify me when available.
You're on the list — we'll be in touch soon.
How it works
Simple MFA integrates with your existing BigCommerce store without touching your theme files.
Install Simple MFA from the BigCommerce App Marketplace. OAuth handles permissions automatically — no manual API key setup.
Copy the generated script tag from the admin panel and paste it into Storefront → Script Manager. That's the only storefront change needed.
Login links are transparently redirected to a hosted, branded login page. Customers set a password on first login and can optionally enrol in TOTP MFA.
Features
Passwords are hashed using PBKDF2-SHA256 (NIST SP 800-63B compliant) and stored securely — entirely separate from BigCommerce.
Customers can enrol any RFC 6238 TOTP app — Google Authenticator, Authy, 1Password, and more. Backup codes included.
Existing customers are migrated automatically. A magic link email lets them set their password on first login — no manual re-registration.
Upload your logo and set your brand colours. The hosted login page matches your store identity.
Every login attempt is logged with IP address and user agent. View per-customer history and store-wide suspicious activity from the admin panel.
Automatic lockout after repeated failures. Cloudflare-native threat scoring blocks suspicious IPs before they reach your store.
Compatibility
Simple MFA works with any BigCommerce store running a Stencil theme — including Cornerstone and all marketplace themes.
Pricing
Billing is based on the number of customers with an active account — not logins, not page views. 10% off with annual billing.
Free
$0
Up to 200 credentialed customers
Standard
$12
per 100 customers / month above free tier
Enterprise
Let's talk
10,000+ customer accounts
Pricing is based on credentialed customers active in the previous calendar month — not total BigCommerce customer accounts.
Simple MFA is currently in early access. Leave your email and we'll reach out when it's ready.
No spam. Unsubscribe any time.
You're on the list — we'll be in touch soon.