{"id":413819,"date":"2024-06-29T23:22:12","date_gmt":"2024-06-29T23:22:12","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=413819"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=413819","title":{"rendered":"<span>Easy Two Factor Authentication (2FA) with Google Authenticator<\/span>"},"content":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>With this API implementing two factor authentication (2FA) is easier than ever. Just in 5 minutes I\u2019ll guide you how to generate and validate time-based one-time passwords (TOTP) for second factor authentication (2FA) in fast and secure manner.<\/p>\n<p>1. First we download Google Authenticator app from App Store or Google Play.<\/p>\n<p>I am using my iPhone SE, but of course Google Authenticator app is available for all iOS and Android devices:<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/418\/a2f\/905\/418a2f9059bcedd24685fb9c466cf1c3.png\" width=\"320\" height=\"568\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/418\/a2f\/905\/418a2f9059bcedd24685fb9c466cf1c3.png\"\/><\/figure>\n<p>2. OK, now we have Google Authenticator app installed, but we have no QR codes to assign it to because there is no account information for association with our app. So our next step would be to generate \u201csecret\u201d information and assign it to our account id. Subscribe to <a href=\"https:\/\/rapidapi.com\/chdan\/api\/google-authenticator\/\" rel=\"noopener noreferrer nofollow\">API <\/a>and execute first \/new\/ endpoint. I will be using Postman to show how we run endpoints.<\/p>\n<p>Create a \/new_2\/ request in Postman and provide url and X-Rapidapi-Key (see details here\u00a0<a href=\"https:\/\/rapidapi.com\/chdan\/api\/otp-authenticator\/\" rel=\"noopener noreferrer nofollow\">https:\/\/rapidapi.com\/chdan\/api\/otp-authenticator\/<\/a>):<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/e9e\/325\/f62\/e9e325f6263444eec11a58397fb78147.PNG\" width=\"1013\" height=\"489\"\/><\/figure>\n<p>After successful execution of the \/new_2\/ endpoint you\u2019ll see your new &#171;secret value&#187;<\/p>\n<p>3. Save this secret value, add \u201caccount\u201d and \u201cissuer\u201d into our next \/enroll\/ endpoint. After successful execution of \/enroll\/ service you will have url link generated, so that your users could add this info to Google Authenticator app:<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/b15\/a5a\/534\/b15a5a53410c7db629e81be4582dec1d.png\" width=\"1009\" height=\"506\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b15\/a5a\/534\/b15a5a53410c7db629e81be4582dec1d.png\"\/><\/figure>\n<p>4. Now let\u2019s open this url and scan the QR code:<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/90e\/a57\/11e\/90ea5711ef498f6a38c8a2e6d5d07444.PNG\" width=\"865\" height=\"752\"\/><\/figure>\n<p>Use \u201cScan a QR code\u201d button in Google Authenticator:<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a28\/b1a\/ec5\/a28b1aec560e771628657dd70e210557.PNG\" width=\"320\" height=\"568\"\/><\/figure>\n<p>5. Done! After we synced Google Authenticator app with your server\u2019s secret, Google Authenticator starts generating time-based one-time passwords (TOTP):<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/ce1\/f1c\/c33\/ce1f1cc33f2f221f5167301c3762df79.PNG\" width=\"320\" height=\"568\"\/><\/figure>\n<p>6. Now we can validate one-time passwords (TOTP) on our end using \/validate\/ service:<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b33\/b82\/e76\/b33b82e7626aca156f1f8b99878648b8.PNG\" width=\"1010\" height=\"494\"\/><\/figure>\n<p>\u201cTrue\u201d value indicates correct entry. After 60 seconds the same request would return \u201cFalse\u201d value.<\/p>\n<p>Why are one-time passwords (TOTP) valid even after TOTP disappeared in Google Authenticator app? Google Authenticator shows one-time passwords for 30 seconds only and then it generates new TOTPs. We however assign 60 seconds validity of one-time codes on server side to give our users and systems additional 30 seconds to finish authentication process.<\/p>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/576200\/\"> https:\/\/habr.com\/ru\/articles\/576200\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>With this API implementing two factor authentication (2FA) is easier than ever. Just in 5 minutes I\u2019ll guide you how to generate and validate time-based one-time passwords (TOTP) for second factor authentication (2FA) in fast and secure manner.<\/p>\n<p>1. First we download Google Authenticator app from App Store or Google Play.<\/p>\n<p>I am using my iPhone SE, but of course Google Authenticator app is available for all iOS and Android devices:<\/p>\n<figure class=\"\"><\/figure>\n<p>2. OK, now we have Google Authenticator app installed, but we have no QR codes to assign it to because there is no account information for association with our app. So our next step would be to generate \u201csecret\u201d information and assign it to our account id. Subscribe to <a href=\"https:\/\/rapidapi.com\/chdan\/api\/google-authenticator\/\" rel=\"noopener noreferrer nofollow\">API <\/a>and execute first \/new\/ endpoint. I will be using Postman to show how we run endpoints.<\/p>\n<p>Create a \/new_2\/ request in Postman and provide url and X-Rapidapi-Key (see details here\u00a0<a href=\"https:\/\/rapidapi.com\/chdan\/api\/otp-authenticator\/\" rel=\"noopener noreferrer nofollow\">https:\/\/rapidapi.com\/chdan\/api\/otp-authenticator\/<\/a>):<\/p>\n<figure class=\"full-width\"><\/figure>\n<p>After successful execution of the \/new_2\/ endpoint you\u2019ll see your new &#171;secret value&#187;<\/p>\n<p>3. Save this secret value, add \u201caccount\u201d and \u201cissuer\u201d into our next \/enroll\/ endpoint. After successful execution of \/enroll\/ service you will have url link generated, so that your users could add this info to Google Authenticator app:<\/p>\n<figure class=\"full-width\"><\/figure>\n<p>4. Now let\u2019s open this url and scan the QR code:<\/p>\n<figure class=\"full-width\"><\/figure>\n<p>Use \u201cScan a QR code\u201d button in Google Authenticator:<\/p>\n<figure class=\"\"><\/figure>\n<p>5. Done! After we synced Google Authenticator app with your server\u2019s secret, Google Authenticator starts generating time-based one-time passwords (TOTP):<\/p>\n<figure class=\"\"><\/figure>\n<p>6. Now we can validate one-time passwords (TOTP) on our end using \/validate\/ service:<\/p>\n<figure class=\"full-width\"><\/figure>\n<p>\u201cTrue\u201d value indicates correct entry. After 60 seconds the same request would return \u201cFalse\u201d value.<\/p>\n<p>Why are one-time passwords (TOTP) valid even after TOTP disappeared in Google Authenticator app? Google Authenticator shows one-time passwords for 30 seconds only and then it generates new TOTPs. We however assign 60 seconds validity of one-time codes on server side to give our users and systems additional 30 seconds to finish authentication process.<\/p>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/576200\/\"> https:\/\/habr.com\/ru\/articles\/576200\/<\/a><br \/><\/br><\/br><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-413819","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/413819","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=413819"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/413819\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=413819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=413819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=413819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}