One Time Password
On this page
Authelia supports Time-based One-Time Passwords generated by apps like Google Authenticator.
data:image/s3,"s3://crabby-images/8318c/8318c8cbcafdd4776af64c2b5627fcfbbe76caf3" alt="Second Factor OTP Authentication View"
After having successfully completed the first factor, select One-Time Password method option and click on Register device link. This will e-mail you to confirm your identity.
NOTE: If you’re testing Authelia, this e-mail has likely been sent to the mailbox available at https://mail.example.com:8080/
Once this validation step is completed, a QR Code gets displayed.
data:image/s3,"s3://crabby-images/49c94/49c94a0dc45455e232d840b8e4e36733a10d9ee8" alt="Second Factor OTP Registration View"
You can then use Google Authenticator or an authenticator of your choice to scan the code in order to register your device.
data:image/s3,"s3://crabby-images/c9837/c98371e314c1b2cb7545d7f77317f7416828bbc5" alt="Second Factor OTP Registration View"
From now on, you get tokens generated every 30 seconds that you can use to validate the second factor in Authelia.
Limitations
Users currently can only enroll a single TOTP device in Authelia. This is standard practice, as a user can obviously register a second device with the same QR Code. As there is no tangible benefit and it is harder to keep track of multiple devices it’s not a feature we will implement.