Last updated: Jan 29, 2026, 3:03 PM
| Check out our other login-related content for more information:
|
Multi-factor authentication (MFA) is one of the simplest and most effective ways for you to protect your account and access to proprietary business information and operations. MFA adds an extra layer of security by requiring additional verification beyond your email/password, which is critical given how easily passwords can be stolen or guessed. Similar to your bank, Toast is doing this to ensure the financial safety of all our customers from bad actors.
This security process is associated with your login. You choose to get a six-digit passcode sent via SMS, or you can use an authenticator app to get the code.
This additional layer stops cybercriminals from accessing sensitive data even if they manage to obtain your password, protecting against phishing attacks and identity theft. By using MFA, you can not only keep your account safe, but also gain peace of mind knowing your information is significantly better protected from unauthorized access.
Toast offers two main types of multi-factor authentication for your Toast Web login.
MFA will be required for users with 8.1 Financial Accounts and 8.7 Instant Deposits permissions, as well as some Toast Payroll users. For this reason, it's strongly recommended that each user has their own Toast Web account/login, rather than sharing one login for multiple users at your business. See to learn more.
Toast understands that some users share an account to log in to a Toast platform. However, with the implementation of MFA, users should look to create their own individual accounts so they will have access without relying on another person's MFA code or without acting under another person's identity.
Another way around this is to create a shared manager account that does not allow changes to sensitive information. Permission 4.1 Sales Reports is an example of a view-only permission that doesn't allow user to change any information. Or maybe you allow all FOH managers the 5. Quick Edit Access permission group so they can change the menu, but don't give them the 8. Account Admin permission group. Check out to learn more.
To set up multi-factor authentication for your account, follow these steps.
Note: You may encounter MFA while logging in. If so, skip down to step 5.
You're all set! In general, you can expect an MFA challenge about every 30 days per device (e.g. computer, laptop, mobile phone).
MFA does not apply when logging in on your POS device.
You must have access to your device in order to disable or reset MFA. If you lose your mobile device and you need to update your MFA, your authentication code is being sent to the wrong number, or if you're unable to log in to Toast Web to update MFA, contact Customer Care for assistance.
If you'd like to switch between the two authentication methods (SMS text and authenticator app), you can reset MFA on your own. If your account doesn't have any sensitive permissions (8.1 Financial Accounts or 8.7 Instant Deposits), you can also choose to disable MFA.
MFA setup will be required for some Toast Payroll users, and any users with access to sensitive permissions (8.1 Financial Accounts or 8.7 Instant Deposits). Other users can skip setting up MFA.
The MyToast app will also use the same MFA protocols.
If you’ve already set up MFA but you cannot access your MFA code, you will not be able to log into Toast. Contact Customer Care for assistance.
If you're not receiving the text message with your authentication code, double-check the phone number you have entered in. You can also try clearing your cache and cookies and attempting to send the MFA code again. If you try to resend the code and you still do not receive it, contact Customer Care.
If you're regularly having trouble receiving the SMS message with your authentication code, consider resetting MFA and using an authenticator app instead.
We recommend that every employee who needs Toast Web access should have their own profile so they can log in independently. This way, only users with sensitive financial permissions will be required to enable MFA. To learn more about the login and security benefits of individual accounts, see
If multiple people are trying to use the same device (computer, laptop, tablet, etc.) to log in to Toast Web, you may run into the scenario where the last person's email is saved on the login screen and the wrong person is getting a text with a 6-digit MFA code. A workaround in this case would be to either clear the cache & cookies on your browser, or open a private/icognito tab so that the second user can enter their own email and password.