Install Guide

Up and running in under 30 minutes

Follow the steps below to add MFA to your BigCommerce storefront. Most steps take minutes — one requires a small theme file change that any developer can complete quickly if needed.

Prerequisites

Make sure you have the following in place before installing.

Step-by-step checklist

1

Install Simple MFA from the BigCommerce App Marketplace

~2 minutes

Find Simple MFA in the BigCommerce App Marketplace and click Install. You'll be redirected through BigCommerce's OAuth flow, which grants Simple MFA the permissions it needs to create customer login sessions. No API keys or manual configuration required.

Permissions requested: read customer accounts, read store information, issue customer login tokens.

2

Complete the guided setup in the admin panel

~5 minutes

After installing, you'll be taken to the Simple MFA admin panel inside BigCommerce. A short setup checklist walks you through:

  • Confirming your store details
  • Configuring your email sender name
  • Setting your branding (Standard plan)
  • Choosing your MFA policy (optional or mandatory)
You can return to any of these settings at any time from the admin panel.
3

Update your theme's login page template

~5 minutes

To fully secure your storefront, the native BigCommerce login page needs to be replaced. Without this change, a customer who navigates directly to /login/ could bypass Simple MFA entirely.

In the Simple MFA admin panel, go to Setup → Theme file. You'll find the complete replacement content for your theme's templates/pages/auth/login.html file. Copy the content and replace the existing file in your theme using the BigCommerce Theme Editor or by editing your theme files directly.

Comfortable editing theme files? This is a straightforward file replacement — the full content is provided and takes a few minutes. If you'd prefer not to edit theme files yourself, any BigCommerce developer can complete this step quickly.

Guided automatic installation of this change is coming soon and will handle this step for you.
4

Copy your storefront script tag

~1 minute

In the Simple MFA admin panel, go to Setup → Script tag. You'll see a pre-generated script snippet specific to your store. Copy the entire snippet — you'll paste it into BigCommerce in the next step.

The script tag is unique to your store. Do not share it or use another store's snippet.
5

Add the script to BigCommerce Script Manager

~2 minutes

In your BigCommerce admin, go to Storefront → Script Manager and click Create a Script. Configure it as follows:

  • Name: Simple MFA
  • Location on page: Footer
  • Select pages where script will be added: All pages
  • Script type: Script

Paste the script snippet into the Script contents field and click Save.

6

Test the login flow with your test account

~5 minutes

Open your storefront in a private/incognito browser window and click the account login link. You should be redirected to the Simple MFA login page instead of the standard BigCommerce login.

Enter the email address of your test customer. You'll receive a magic link email — click it to set a password and complete the account claim. Then test logging in with that password, and optionally enrol in TOTP MFA.

If you are not redirected to Simple MFA, check that the script was saved correctly in Script Manager and that your browser cache is cleared.
7

Let your customers know

Your timeline

Simple MFA is now live for all customers on your storefront. The account claim flow is automatic and self-service — customers will be guided through setting their password on their first login.

Optionally, send your customers a heads-up email explaining that your login process has been upgraded for their security. This reduces confusion and support requests when they encounter the new login page for the first time.

Need a template? Email [email protected] and we'll send you one.

Common issues

Customers are not being redirected to the Simple MFA login page

Check that the script tag is saved correctly in Script Manager and set to load on All pages in the Footer. Clear your browser cache and try again in a fresh private window. If the issue persists, copy the script tag again from the Simple MFA admin panel — it may have been accidentally truncated when pasting.

The magic link email is not arriving

Check the spam/junk folder first. If it's not there, verify that the email address exists as a customer in your BigCommerce admin. For new stores in early access, there may be a short delay on the first email send. If the problem persists, contact [email protected].

After login, the customer is not redirected back to the store

This usually means the store_v2_customers_login permission scope is missing from the app installation. Try uninstalling and reinstalling Simple MFA from the BigCommerce App Marketplace to re-trigger the OAuth flow with the correct scopes.

I need help with something not listed here

Email [email protected] and we'll get back to you. During early access, support is handled directly by the founder.

Ready to install?

Simple MFA is currently in early access. Leave your email and we'll reach out when it's ready.

No spam. Unsubscribe any time.

You're on the list — we'll be in touch soon.