When a Payhawk Administrator has enabled the 2FA extra security layer for your company, you will be automatically logged out of your personal Payhawk account. Upon your next login and depending on the 2FA option enabled, you will be required to authenticate.
Your first name, last name, and a verified phone number are required to use Payhawk. These details aren't part of push authentication or MFA itself - however, the SMS code for two-factor authentication is only sent to a phone number you've already verified.
You'll normally provide this information during onboarding. However, if any of these details are missing, you'll be prompted to complete them the next time you log in. This applies to every login, regardless of your authentication factor and whether you're using the Web Portal or the Mobile App.
Ways to authenticate in Payhawk
In Payhawk, you can authenticate in the following ways:
Authenticate with a six-digit code received as an SMS or email to your verified phone number or email address. Your verified number or email address is the one with which you are registered in Payhawk.
Authenticate with a push notification on the Payhawk Mobile App from a trusted device you have previously linked to your personal Payhawk account.
When you log in to the Payhawk Mobile App on your trusted device, the app confirms the push notification for you, and you go straight in.
A Payhawk Web Portal login always sends the notification to your trusted device for you to confirm.
Registering your first trusted device
Before you can register a trusted device, your phone number must be verified in Payhawk. If it is not verified yet, Payhawk will ask you to verify it before you start.
When you start registering your first trusted device and depending on where you log in, Payhawk will prompt you in either of the following ways:
In the Payhawk Web Portal, a screen titled Secure your account asks you to set up a trusted device. The screen shows a QR code and a Download the mobile app link. A Skip for later link appears when another authentication method is available to you.
In the Payhawk Mobile App, a prompt titled Set this device as trusted appears after you authenticate with an SMS or email code.

To register your phone as a trusted device:
Install the Payhawk Mobile App on your phone.
Log in to the Payhawk Mobile App with the email address you use for Payhawk.
On the Set this device as trusted prompt, tap Confirm. Your phone is now your trusted device.

When the Payhawk Web Portal is waiting on the Secure your account screen, it continues on its own as soon as your device is registered:
The QR code only opens the app store, so scanning it downloads the Payhawk Mobile App but does not register your device as trusted.
When a trusted device is required for your account, tapping Decline on the prompt signs you out, so tap Confirm to finish the setup.
Confirming a login from another device
When you log in to Payhawk from a device that is not your trusted device, Payhawk sends a notification to your trusted device:
On the Check your phone! screen, wait for the notification on your trusted device.
Open the Payhawk Mobile App notification. The Confirm login to Payhawk screen shows where the login attempt comes from. Depending on your account, the screen asks you to tap the number that matches the one shown on the device you are logging in from.

Tap Confirm to allow the login.
You have five minutes to confirm. After that, the Payhawk Web Portal will show Time is over! and you will need to start again. Select Resend notification to send a new notification to your trusted device.
When you tap Decline, Payhawk shows Login declined and no one gets access. Select Try again to start a new login attempt. If you receive a notification for a login you did not start, decline it, change your password, and contact the Payhawk Support team.
Registering an additional trusted device
The following steps assume you already have a trusted device.
You can add as many trusted devices as you wish and at any time.
Adding a trusted device happens in the Payhawk Mobile App.
To register an additional trusted device:
Log into the Payhawk Mobile App on your new device (the 2FA factor doesn’t matter, you just need to log in from the device you want to add as trusted).
In case you have the Push Authentication method enabled as a 2FA, after you’ve logged in, a screen asking you whether you want to add this device as trusted.
Select Yes. As a result, the device is added to your Payhawk account as trusted.
Back in the Payhawk Web Portal, you’ll be able to see the newly added trusted devices for your Payhawk account. To do so, go to the Security > Two-factor authentication tab.
.jpg)
Replacing or removing a trusted device
Removing a trusted device happens in the Payhawk Web Portal.
To remove a trusted device:
Hover over your profile picture, and select the Manage profile option.
Go to the Security > Two-factor authentication tab.
Hover over the device you want to remove and click on the Trash icon.

In the dialog that opens, confirm your choice by clicking on Confirm. As a result, you won’t be able to use the deleted device as a way of authorization until you set this or another device as trusted.
Specifics
If you switch to a new device you want to make trusted in place of an existing trusted device you’ll no longer need, it is recommended that you first remove the old trusted device and then add the new one.
If you remove a trusted device you’d still use from your Payhawk account, the Payhawk Mobile App on that device will keep its earlier setup and will not ask you to trust it again. To use the same device as trusted again, reinstall the Payhawk Mobile App or clear its data, then log into the Payhawk Mobile App and tap Confirm.
If you reinstall the Payhawk Mobile App on a trusted device, the app won’t recognize the device and you’ll need to add it again as a trusted device. However, once this re-adding is done, you’ll be able to see the trusted device twice - one instance from the previous usage before the app reinstallation, and another from the re-addition of the device after the app has been reinstalled. In this case, you need to look at the time of your last login into the trusted device to know which instance is the older one, and remove it from your account.
Signing out of the Payhawk Mobile App does not delete the trusted device; the device will remain trusted and will still receive login notifications. You cannot confirm a login while signed out, but this is not a security risk - you need to log back in to confirm the login request. To stop the notifications, delete the device from the Payhawk Web Portal.
Payhawk emails you each time a trusted device is deleted from your account.
Logging in without your trusted device
When you do not have your trusted device with you, you can still log in with another authentication method, as long as your company has one enabled:
On the Check your phone! screen, select Try signing in another way.
Select Authenticate via text message or Authenticate via email, and enter the six-digit code you receive.
When no other method is available to you, select Lost your trusted device? on the same screen to reach the Payhawk Support team.
If you can’t sign in to your account because you no longer have access to your trusted device, a Payhawk Administrator at your organization must request manual removal of your trusted device.
The Payhawk Administrator needs to email the Payhawk Support team at support@payhawk.com and include a brief note that explains the situation, including the reason for removing the trusted device. This email authorizes Payhawk to remove your old device.
Viewing your trusted devices
To view the trusted devices logged in your account:
In the Payhawk Web Portal, hover over your profile picture.
Select Manage profile > Security > Two-factor authentication.

The list shows the Name, Model, and Last Login of each trusted device. Check the list from time to time, and delete any device you do not recognize.
Useful resources