Skip to main content
Prerequisite: A Base32 TOTP secret (shown during 2FA enrollment) or an otpauth:// URI (often embedded in a QR code).
Generate a time-based 2FA code inside a JavaScript step with the otpauth library, which Momentic preloads in the step sandbox. Reach for this when a login flow asks for an authenticator-app code.

From a Base32 secret

From an otpauth:// URI

Then add a Type step with value {{ env.TOTP_CODE }}.
Store the secret as an environment variable rather than hardcoding it.