mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 18:29:07 +00:00
91 lines
3.9 KiB
Plaintext
91 lines
3.9 KiB
Plaintext
---
|
|
title: "TOTP"
|
|
description: "Learn how to dynamically generate time-based one-time passwords."
|
|
---
|
|
|
|
The Infisical TOTP dynamic secret allows you to generate time-based one-time passwords on demand.
|
|
|
|
## Prerequisite
|
|
|
|
- Infisical requires the OTP url from the TOTP provider.
|
|
|
|
## Set up Dynamic Secrets with TOTP
|
|
|
|
<Steps>
|
|
<Step title="Open Secret Overview Dashboard">
|
|
Open the Secret Overview dashboard and select the environment in which you would like to add a dynamic secret.
|
|
</Step>
|
|
<Step title="Click on the 'Add Dynamic Secret' button">
|
|

|
|
</Step>
|
|
<Step title="Select TOTP">
|
|

|
|
</Step>
|
|
<Step title="Provide the inputs for dynamic secret parameters">
|
|
<ParamField path="Secret Name" type="string" required>
|
|
Name by which you want the secret to be referenced
|
|
</ParamField>
|
|
<ParamField path="Configuration Type" type="string" required>
|
|
There are two supported configuration types - `url` and `manual`.
|
|
|
|
When `url` is selected, you can configure the TOTP generator using the OTP URL.
|
|
|
|
When `manual` is selected, you can configure the TOTP generator using the secret key along with other configurations like period, number of digits, and algorithm.
|
|
</ParamField>
|
|
<ParamField path="URL" type="string">
|
|
OTP URL in `otpauth://` format used to generate TOTP codes.
|
|
</ParamField>
|
|
<ParamField path="Secret Key" type="string">
|
|
Base32 encoded secret used to generate TOTP codes.
|
|
</ParamField>
|
|
<ParamField path="Period" type="number">
|
|
Time interval in seconds between generating new TOTP codes.
|
|
</ParamField>
|
|
<ParamField path="Digits" type="number" required>
|
|
Number of digits to generate in each TOTP code.
|
|
</ParamField>
|
|
<ParamField path="Algorithm" type="string" required>
|
|
Hash algorithm to use when generating TOTP codes. The supported algorithms are sha1, sha256, and sha512.
|
|
</ParamField>
|
|
|
|

|
|

|
|
|
|
</Step>
|
|
<Step title="Click 'Submit'">
|
|
After submitting the form, you will see a dynamic secret created in the dashboard.
|
|
|
|
</Step>
|
|
<Step title="Generate dynamic secrets">
|
|
Once you've successfully configured the dynamic secret, you're ready to generate on-demand TOTPs.
|
|
To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item.
|
|
Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section.
|
|
|
|

|
|

|
|
|
|
|
|
Once you click the `Generate` or the `New Lease` button, a new secret lease will be generated and the TOTP will be shown to you.
|
|
|
|

|
|
|
|
</Step>
|
|
</Steps>
|
|
|
|
## Audit or Revoke Leases
|
|
|
|
Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard.
|
|
This will allow you to see the lease details and delete the lease ahead of its expiration time.
|
|
|
|

|
|
|
|
## Renew Leases
|
|
|
|
To extend the life of the generated dynamic secret lease past its initial time to live, simply click on the **Renew** button as illustrated below.
|
|

|
|
|
|
<Warning>
|
|
Lease renewals cannot exceed the maximum TTL set when configuring the dynamic
|
|
secret.
|
|
</Warning>
|