# Signing in and two-step

Account > Security · Guide · https://vendordue.com/docs/signing-in

**In short:** Inside Shopify, VendorDue opens with no sign-in. To use it in a tab of its own, add a passkey or a password in Settings › Security, and open it inside Shopify at least once every 14 days. An authenticator app adds a second step; a passkey counts as both.

Who: Admin, Viewer. Where: Settings > Security.

Most days you'll open VendorDue from **Apps** in your Shopify admin, and there's nothing to sign in to: Shopify has already told VendorDue who you are. Signing in only matters when you want VendorDue in a tab of its own, or on a phone without the Shopify app.

Inside Shopify, VendorDue's pages are in Shopify's own menu under **VendorDue**, with **Settings** last. A bar across the top holds search, what you owe, the bell and the light or dark switch. In a tab of its own, VendorDue has its own sidebar instead.

## Use VendorDue outside Shopify

In **Settings > Security**, add a way to sign in. Until you do, it reads **No sign-in method outside Shopify**: "Add a passkey or set a password to open VendorDue in its own tab."

- **Passkey**: your fingerprint, face or device lock instead of a password. Press **Add passkey**. Shopify doesn't allow passkeys to be made inside it, so VendorDue offers **Continue in a new tab** first.
- **Password**: press **Set password**. Once you have a passkey, a password is "Optional when you have a passkey."

Then sign in at vendordue.com with your email address.

Inside Shopify, the bar across the top has **Open VendorDue**. One press opens VendorDue in a new tab, already signed in, on the page you were on. On a phone, where the Shopify app has no bar across the top, it sits at the top of **Settings > Account**.

That tab stays signed in for a week. Until you have a passkey or a password, a line at the top of it offers **Set a password**, which opens **Settings > Security** with the password row lit and ready. Once it's saved, VendorDue reminds you where to use it: "Sign in at vendordue.com with" your email. The cross beside the line hides it for good.

> **Recommended:** Use a passkey and no password. A passkey can't be guessed or reused from another site, and it already counts as both steps of a sign-in.

> **Careful:** Open VendorDue inside Shopify at least once every 14 days. Shopify doesn't tell apps when someone leaves a store's staff, so signing in outside Shopify works for 14 days after you last opened VendorDue inside it.

## Two-step sign-in

Set up an **Authenticator app** with **Set up**, and VendorDue asks for its six-digit code after your password: "Scan the code with Google Authenticator, 1Password or any app that shows six digits." A stolen password alone then can't open your store's records.

"A passkey sign-in counts as both steps", so with a passkey there's no code to type.

When you enter a code on a computer you use often, tick **Trust this device for 30 days**, and it won't ask there again until then. Trusted devices are listed under Two-step authentication, each with "Skips two-step until" a date, and **Remove** beside it.

An Admin can make two-step required for the whole team with **Require two-step authentication** in **Settings > Team**. Then anyone without an authenticator app sets one up the next time they sign in outside Shopify. It stays on while PayPal is connected. See [Before money moves](https://vendordue.com/docs/before-money-moves).

## Devices

**Devices** lists every browser signed in to your account outside Shopify. Press **Sign out** beside any you don't recognise, or **Sign out all other devices**.

Changing your password, or removing a passkey or your authenticator app, signs out every other device. Adding one doesn't.

## When it looks wrong

### I forgot my password

On the sign-in page, press **Forgot password?**. "We sent six digits to your inbox. You choose a new password next." Nobody at VendorDue can see or set your password for you.

### It keeps asking me to sign in

It's been more than 14 days since you opened VendorDue inside Shopify. Open it once from **Apps** in your Shopify admin, then sign in outside Shopify again.

### My authenticator app was on a phone I lost

Sign in with a passkey if you have one. If not, open VendorDue inside Shopify. Shopify's own sign-in already proved it's you, so in **Settings > Security** you can **Remove** the old authenticator and **Set up** a new one. There are no backup codes to keep.

### "Passkeys can't be created inside Shopify"

That's Shopify's rule for apps inside its admin. Press **Continue in a new tab**, and add the passkey there.

## Common questions

**Do I need a VendorDue password at all?** No. If you only ever open VendorDue inside Shopify, you never sign in.

**Do my vendors sign in the same way?** They use the same sign-in page, and land on their own page. Your team's two-step rule never applies to them; they choose their own. See Signing in, and several stores.

**What if I'm also a vendor at another store?** One browser can be signed in on both sides. VendorDue asks **Continue as**: Your store, or Your payouts.

Checked against VendorDue on 2026-10-08.
