How shp888 Two-Factor Authentication Works on Mobile
We offer two main 2FA methods on shp888: authenticator app (such as Google Authenticator or Authy) and SMS-based codes. When you enable 2FA in your account settings, we show you a QR code to scan with your authenticator app, or we send a verification link via SMS to your registered phone number.
On your first login after enabling 2FA, we ask for both your password and a six-digit code from your chosen method. Our system validates the code in real time—if it's correct, we grant access; if it's wrong or expired, we deny the attempt and log it in your account history. This happens instantly, so there's no delay between entering your credentials and reaching your dashboard.
Authenticator App Method
We recommend the authenticator app route because it doesn't rely on SMS delivery delays or international roaming issues. You download an app like Google Authenticator, Microsoft Authenticator, or Authy to your Android or iPhone, then scan our QR code from your shp888 account settings. The app generates a new six-digit code every 30 seconds—you use the current code whenever we ask for 2FA verification.
The authenticator app works even when your phone is in airplane mode or offline, which is handy if you're traveling during Idul Fitri or Idul Adha holidays and want to check your account on the flight. Once you've scanned our QR code, the app stores the secret key locally on your phone, so the codes are always available.
SMS-Based Method
If you prefer SMS, we send a six-digit code to your registered mobile number whenever we need 2FA verification. This method is simpler to set up—no QR code, no app download—but it depends on your carrier delivering the SMS quickly. In Jakarta, Surabaya, Bandung, and Medan, SMS arrival is usually instant, but international or roaming delays can occasionally occur.
We use SMS for critical actions like password resets and large withdrawals, even if you've enabled the authenticator app, to add redundancy. This way, if your phone is lost, we still have SMS as a backup verification channel.
Setting Up 2FA on shp888 Mobile
On our Android app or iOS mobile browser, go to your account settings, then tap "Security" or "Privacy & Security." You'll see the option "Enable Two-Factor Authentication." Tap it, and we'll show you a QR code (if you choose the app method) or ask you to confirm your phone number (if you choose SMS).
- Open Account Settings: Tap your profile icon in the shp888 app, then select "Account" or "Settings."
- Navigate to Security: Scroll down and tap "Two-Factor Authentication" or "2FA Setup."
- Choose Your Method: Select "Authenticator App" or "SMS Code." For the app, we'll display the QR code; for SMS, we'll verify your phone number.
- Confirm Activation: Enter a code from your chosen method to prove it works, then tap "Enable 2FA."
- Save Backup Codes: We display ten backup codes. Screenshot or write them down, then store them securely offline.
The entire process takes under three minutes. After activation, 2FA is live—on your next login to shp888 from any device, we'll ask for your six-digit code.
When 2FA Is Required on shp888
We ask for 2FA verification in these situations:
- New device login: Your first login to shp888 from a new phone, tablet, or web browser triggers 2FA.
- Password reset: When you reset your password, we confirm your identity with a 2FA code before letting you create a new one.
- Large withdrawals: Withdrawals above a certain amount (we notify you of the threshold in your account) require 2FA as an extra safeguard.
- Account recovery: If you've locked yourself out, we use 2FA codes to verify it's really you before restoring access.
- Payment method changes: Adding or removing a bank account, DANA, e-wallet, mobile banking, local payment, online payment, or e-wallet linked account requires 2FA verification.
Regular logins from a device we recognize do not require 2FA every time—we remember your device for 30 days unless you clear your browser cache or log out. This balances security with convenience: you get strong protection without constant friction.
Recovering Your Account If You Lose 2FA Access
If your phone is lost, stolen, or you delete your authenticator app without saving backup codes, our support team can help you regain access. Contact us through our in-app help chat or email support—we'll ask you to verify your identity through KYC documents (identity card, selfie, or address proof) and confirm your registered email or phone number.
Once we confirm you're the account holder, we can temporarily disable 2FA so you can log back in. Then, from a trusted device, we recommend immediately re-enabling 2FA with a new authenticator app or SMS setup.
2FA on Desktop vs. Mobile shp888
Our 2FA system works identically on desktop and mobile—the same codes work everywhere. If you enable 2FA on our Android app, it applies to your shp888 account globally. When you later log in via iOS or desktop browser, we'll ask for the same authenticator code or SMS verification.
However, the recovery flow is streamlined on mobile. Our iOS browser and Android app have built-in prompts for entering the 2FA code, while desktop users must manually type it into a web form. Either way, the security level is the same.
Best Practices for 2FA Security
- Use an authenticator app over SMS: Authenticator apps are more resistant to SIM-swap fraud and don't depend on carrier delivery.
- Back up your QR code or secret key: Take a screenshot of the QR code or write down the 16-character secret key before confirming 2FA, so you can restore access if you switch phones.
- Save your backup codes: We provide ten one-time codes—store them in a secure location, not on your phone or in an unsecured cloud folder.
- Do not share your codes: Never give anyone—even our support team—your authenticator codes or backup codes. We'll never ask for them.
- Update your authenticator app: Keep your authenticator app (Google Authenticator, Authy, etc.) up to date on your Android or iOS device.
- Register multiple devices: If you use shp888 on both Android and iOS, set up authenticator apps on both so you're covered if one device fails.
Common 2FA Questions on shp888
- Does 2FA slow down login?
- No. The six-digit code entry adds 10–15 seconds to your login time, and only on a new device. Our system validates codes instantly.
- Can I disable 2FA later?
- Yes, you can disable 2FA in account settings anytime. We'll ask for a 2FA code to confirm the disabling itself, for security.
- What if my code expires?
- Authenticator codes change every 30 seconds. If you enter an expired code, wait for the next one or try the previous one (both are valid for a few seconds of overlap).
- Is SMS 2FA safe outside Indonesia?
- Yes, but roaming delays can occur. If you're traveling to Idul Fitri celebrations abroad, use an authenticator app to avoid SMS delays.
