Skip to main content

Migrate from WP 2FA

Migrate from WP 2FA

Last verified: 2026-06-11

This is a checklist, not an importer. It helps you move deliberately while keeping a recovery path.

WP 2FA is a strong product. This guide is for teams choosing Awthy's focused recovery and WooCommerce account-security workflow instead of a broader two-factor plugin.

Before you start

  • Confirm at least one administrator can sign in.
  • Save current recovery codes or emergency access instructions from the existing plugin.
  • Install Awthy without disabling the existing plugin.
  • Set up Awthy two-factor authentication and recovery codes for one administrator.

Do not disable WP 2FA until Awthy recovery is verified for at least one administrator.

Migration checklist

  • Verify Awthy sign-in for one administrator.
  • Verify recovery codes before enforcing a policy.
  • Decide whether customers are optional, invited, or excluded for now.
  • Disable the old plugin only after Awthy sign-in and recovery are tested.

What does not migrate automatically

  • Existing authenticator-app secrets.
  • Existing passkeys or WebAuthn credentials.
  • Existing recovery codes.
  • Existing trusted-device cookies.

Rollback

If sign-in fails, use the old plugin's documented recovery path or Awthy recovery codes before changing enforcement settings.