TOTP · 2FA for AI agents
Your agent can handle 2FA.
Store TOTP seeds and generate 6-digit codes on demand. Combined with email-based verification, agents complete any authentication flow autonomously.
A fresh code, on demand.
Call vault.totp(name) and get a valid 6-digit code with the exact seconds remaining until the next rotation. Your agent decides whether to use the current code or wait two seconds for a fresh one — avoiding failed logins from near-expiry codes.
vault.totp("gh-deploy")
current code
742 198
expires in 23s
Two factors. Zero humans.
A service emails a verification code? The agent reads it from extractedText. A service requires a TOTP authenticator? The agent generates the code from its vault. Email-based and authenticator-based 2FA — both handled, end-to-end.
Email factor
extractedText
Your code is 8 4 1 6 0 3
TOTP factor
vault.totp
code 7 4 2 1 9 8 · 23s
authenticated · zero humans
Even the API can't leak them.
TOTP seeds are AES-256-GCM encrypted at rest and never returned via any endpoint. Only the time-limited 6-digit codes are accessible — and they expire in 30 seconds. Even if an API key is compromised, the underlying seed remains protected.
access policy
vault.totp(name)
returns 6-digit code · 30s window
allowed
vault.get(name).secret
seed never returned · ever
blocked
seed at rest
AES-256-GCM · per-credential DEK
allowed
api compromise · seed safe
The capabilities
Built for autonomous 2FA flows.
- TOTP code generation: Store the seed once. Generate valid 6-digit codes on demand. RFC 6238 compliant — SHA-1, SHA-256, configurable digits.
- Seeds never exposed: TOTP seeds are AES-256-GCM encrypted and never returned via the API. Only the time-limited 6-digit codes are accessible.
- Remaining time awareness: Every TOTP response includes seconds-until-expiry. Your agent decides whether to use the current code or wait for a fresh one.
- Autonomous registration: Agent signs up, receives verification email, extracts code, completes signup, scans the TOTP QR seed, stores everything in Vault.
- MCP integration: Generate TOTP codes from Claude Desktop, Cursor, or any MCP client using
vault.totp. Combined withvault.getfor full login flows. - Security-first design: Codes are time-bound, scoped per identity, and audit-logged. Even an exposed API key can't leak the underlying TOTP seed.
Where TOTP unlocks autonomy.
- Third-party service login: Logs into GitHub, AWS Console, Salesforce — any 2FA-protected service. Retrieves credentials from Vault and generates a fresh code.
- Account provisioning at scale: Agents register on platforms, verify email, enable 2FA, store all credentials. Onboard your AI workforce to dozens of services.
- Security-compliant automation: Many enterprise tools require 2FA for API and console access. TOTP keeps your agents compliant without breaking autonomy.
- Regulated portal access: Government portals, compliance platforms, regulated services that mandate 2FA. Generate codes on demand, log in, report back.
- Financial platform access: Banking APIs, payment dashboards, financial tools that require 2FA. Authenticate, perform transactions, log out — with audit trail.
- Recovery & re-authentication: When sessions expire, agents re-authenticate automatically with fresh TOTP codes. No alerts, no stale sessions, no broken workflows.
Give your agent a second factor.
Store TOTP seeds, generate codes on demand, complete any 2FA flow autonomously.