For the complete documentation index, see llms.txt. This page is also available as Markdown.

User Profile

While the creation and permission-/role supervision is in the hands of the merchant user administrator, a user still has the ability to change certain things about their login, like the e-mail, name, and password. This chapter covers all areas all individual users have access to, regardless of permission, aka their user profile.

Accessing the user profile

To access their user profile, the user simply has to click on their username at the bottom left of the Backoffice web page, once they have logged in.

There, one can access your language settings, log out and you can access one's basic profile settings.

Basic Settings

You'll first be greeted with the basic settings, where a user can change their name and the language which they want to receive e-mails in.

Change email (username)

Here, the user can change their email address, which will also be used for any kind of notification, like sending password reset links.

After you have set your new e-mail, we will send a verification e-mail to that address.

Change password

As the name suggests, this tab allows the user to change their password.

The password rules will appear as soon as you start typing your new password.

Change appearance

The Backoffice offers a light and a dark mode. You can change between modes by clicking on Change appearance in the navigation menu.

There, you'll have the option to choose between said modes directly, or to use the default of your operating system.

Enable Two-Factor Authentication (2FA)

To enable 2FA, a user has to first set it up.

Saferpay highly recommends using 2FA, as it offers additional security against account theft.

What is 2FA and why should I use it?

As the rate of cyberattacks increases with each year, so does the number of hacked accounts. It becomes apparent that the old User|Password system no longer provides enough security to secure highly valuable logins, like your Saferpay login.

If this login would be compromised, e.g. by password theft and the like, an attacker would, in the worst case, be able to execute all sorts of malicious actions on your account. For example, executing refunds for shipped goods, or transferring money to unwanted places.

This is where 2FA comes in.

2FA is an additional hurdle for an attacker to overcome during login, by requiring an additional OTP code (Factor) to be entered. That is where the "2" in 2FA comes from. It is the second factor of authentication, in addition to your password, which is the first factor.

The second factor is deliberately separated from the first, so that in case of the theft of one of those factors, the other factor is still uncompromised. Since both factors are needed for login, an attacker will be unable to log into your account with just knowing one of the two needed factors.

Restricted services without 2FA

Security concerns and PCI compliance dictate that Saferpay only offers certain functions with 2FA enabled.

The following services are only available if 2FA has been activated:

  • PAN decryption within transaction details

  • Unreferenced refunds (credits) within the Backoffice

Further note that a password reset also requires you to enter your 2FA code if 2FA has been activated. It is not a requirement for a password reset in general, however.

Requirements

  • A user that has been created with the user administration.

  • An OTP-capable authenticator app on your phone

    • Like Google- or Microsoft Authenticator

Setup

1 - In order to activate 2FA, please navigate to your user settings and then to Two-Factor Authentication.

2 - Once there, please open up the OTP authenticator on your phone and create a new entry.

3 - When asked, please scan the QR code from the Saferpay Backoffice.

4 - Enter the the OTP code generated by the app and your login password, then click on Save.

All done. Two-factor authentication is now active on your account.

This is also the place where you can deactivate 2FA if you need to.

Login

Once activated, you'll now be asked to enter the app-generated OTP code on login after entering your username and password.

2FA reset

If a 2FA reset for a user is needed, but the user cannot do it themselves, it can also be done by a merchant user-administrator.

Last updated

Was this helpful?