TOTP · 2FA for AI agents

Your agent can handle 2FA.

Store TOTP seeds and generate 6-digit codes on demand. Combined with email-based verification, agents complete any authentication flow autonomously.

A fresh code, on demand.

Call vault.totp(name) and get a valid 6-digit code with the exact seconds remaining until the next rotation. Your agent decides whether to use the current code or wait two seconds for a fresh one — avoiding failed logins from near-expiry codes.

vault.totp("gh-deploy")

current code
742 198
expires in 23s

Two factors. Zero humans.

A service emails a verification code? The agent reads it from extractedText. A service requires a TOTP authenticator? The agent generates the code from its vault. Email-based and authenticator-based 2FA — both handled, end-to-end.

Email factor
extractedText
Your code is 8 4 1 6 0 3

TOTP factor
vault.totp
code 7 4 2 1 9 8 · 23s
authenticated · zero humans

Even the API can't leak them.

TOTP seeds are AES-256-GCM encrypted at rest and never returned via any endpoint. Only the time-limited 6-digit codes are accessible — and they expire in 30 seconds. Even if an API key is compromised, the underlying seed remains protected.

access policy
vault.totp(name)
returns 6-digit code · 30s window
allowed
vault.get(name).secret
seed never returned · ever
blocked
seed at rest
AES-256-GCM · per-credential DEK
allowed
api compromise · seed safe

The capabilities

Built for autonomous 2FA flows.

  • TOTP code generation: Store the seed once. Generate valid 6-digit codes on demand. RFC 6238 compliant — SHA-1, SHA-256, configurable digits.
  • Seeds never exposed: TOTP seeds are AES-256-GCM encrypted and never returned via the API. Only the time-limited 6-digit codes are accessible.
  • Remaining time awareness: Every TOTP response includes seconds-until-expiry. Your agent decides whether to use the current code or wait for a fresh one.
  • Autonomous registration: Agent signs up, receives verification email, extracts code, completes signup, scans the TOTP QR seed, stores everything in Vault.
  • MCP integration: Generate TOTP codes from Claude Desktop, Cursor, or any MCP client using vault.totp. Combined with vault.get for full login flows.
  • Security-first design: Codes are time-bound, scoped per identity, and audit-logged. Even an exposed API key can't leak the underlying TOTP seed.

Where TOTP unlocks autonomy.

  • Third-party service login: Logs into GitHub, AWS Console, Salesforce — any 2FA-protected service. Retrieves credentials from Vault and generates a fresh code.
  • Account provisioning at scale: Agents register on platforms, verify email, enable 2FA, store all credentials. Onboard your AI workforce to dozens of services.
  • Security-compliant automation: Many enterprise tools require 2FA for API and console access. TOTP keeps your agents compliant without breaking autonomy.
  • Regulated portal access: Government portals, compliance platforms, regulated services that mandate 2FA. Generate codes on demand, log in, report back.
  • Financial platform access: Banking APIs, payment dashboards, financial tools that require 2FA. Authenticate, perform transactions, log out — with audit trail.
  • Recovery & re-authentication: When sessions expire, agents re-authenticate automatically with fresh TOTP codes. No alerts, no stale sessions, no broken workflows.

Give your agent a second factor.

Store TOTP seeds, generate codes on demand, complete any 2FA flow autonomously.