AccountSecurity
How it works
Before money moves
In short
Anything that sends money or opens vendors' payment addresses asks you to confirm it's you, even when you're already signed in. Sending through PayPal takes a passkey or an authenticator app; recording a payment you made yourself asks nothing extra. New ways to confirm wait 24 hours before they can send money.
Being signed in proves someone opened VendorDue. It doesn't prove who is at the keyboard now. So the few actions that would hurt most in the wrong hands ask once more, on the spot: "Confirm it is you before moving money."
What asks, and what it takes#
| You're about to | It asks for |
|---|---|
| Press Send now, or Ask PayPal again | A passkey or an authenticator app |
| Connect or disconnect PayPal | A passkey or an authenticator app |
| Download a PayPal or Wise file, or Download everything owed | Any way you sign in. Inside Shopify, nothing more |
| Prepare or download a copy of your data | Any way you sign in. Inside Shopify, nothing more |
| Start over, when it removes PayPal or payment records, or delete the workspace | A passkey, an authenticator app, or a code we email you |
| Record a payment, issue a check, Pay now | Nothing extra. You moved that money yourself |
Once you've confirmed, it doesn't ask again for 5 minutes, so paying several vendors in a row is one question.
A password or an emailed code is never enough to send money. Those are exactly what someone gets from a reused password or a broken-into inbox.
Inside Shopify#
Inside your Shopify admin, use an authenticator app: "Passkeys do not work inside Shopify Admin." VendorDue offers two ways on:
- Use your passkey in its own tab: VendorDue opens in a tab of its own, where the passkey works.
- Set up an authenticator app instead: scan the code there and then.
The 24-hour wait#
Two rules stop someone who got into your email from paying themselves the same day:
- A new passkey or authenticator app can send money 24 hours after it's added: "Yours can from" a time it names. Inside Shopify, a code from your authenticator app works straight away. Your very first one, set up inside Shopify, has no wait.
- Removing one without confirming with a passkey or authenticator app holds every money action for 24 hours, inside Shopify too.
Who hears about it#
- PayPal connected or PayPal disconnected: the store owner gets an email saying who did it. The connected email has Disconnect PayPal, which works once, for a day.
- A vendor's new PayPal or Venmo address waits 48 hours before any payment goes there. The vendor's sign-in email and their old address both hear about it, with Stop this change. See Send now with PayPal.
When it looks wrong#
"Not ready to move money yet"#
Either a passkey or authenticator app was added in the last 24 hours, or one was removed without confirming. The message says from when you can send again. Until then, you can still record payments you make yourself. If nobody on your side added or removed one, change your password and check Settings, then Security.
I don't have a passkey or an authenticator app#
The question offers to set up an authenticator app right there. If you're inside Shopify, it has no wait.
It asks every time I download#
The proof lasts 5 minutes. Downloading inside Shopify never asks.
Common questions#
- Can a Viewer send money?
- No. Only an Admin can, and only after confirming. See Admin and Viewer. More
- Does VendorDue ever send money without someone pressing Send?
- Never. Send now is the only way money leaves through VendorDue, and only when someone presses it and confirms. More
- Why doesn't recording a payment ask?
- Recording writes down money you already moved, by check or transfer. Nothing leaves your accounts through VendorDue. More
Thanks. We read every answer.
Checked against VendorDue on 6 Oct 2026. What's new