Account Access Management & Permissions
Time-Based One-Time Passwords for Phone Support

Time-Based One-Time Passwords for Phone Support

4/17/2020 · Junade Ali, Andronicus Riyono

What this post added

This post introduces Time-Based One-Time Passwords (TOTP) for Enterprise customer phone support. It details how customers can generate single-use tokens from the Cloudflare dashboard or use a 2FA app to authenticate themselves over the phone, enhancing account security and enabling greater support without relying solely on support tickets. The post also explains the underlying TOTP mechanism (RFC 6238) and Cloudflare's specific implementation for both dashboard-generated tokens and authenticator app integration, including a mechanism to validate tokens from the previous time step to account for network delays.

Read the original post ↗