Produces the six-digit authenticator code for a test account, so a login with 2FA can run with nobody there.
util.totp
The piece
Produce the 6-digit authenticator code for a test account, so a login with 2FA can run unattended. Feed it to the next Input Text as {{ $2FA Code (TOTP).json.code }}.
Reach for it when
A test account with two-factor turned on — which is most of them now.
A scheduled run that would otherwise stop at the code box forever.
2FA Code (TOTP)
Idle
In the bag
Every setting this block has. A field marked only when appears once you have chosen the mode above it — those are alternatives to each other, not extra things to fill in.
Setup keyRequired
write-only
The base32 key the service showed next to the QR code when you set up the authenticator (an otpauth:// link works too, and its own digits/period win). Use “Save as credential” to keep it out of the workflow — typed here it travels with the workflow, so publishing one would publish the key.
Almost always 6. Change it only if the service asked for something else.
Refresh every
starts at 30
Seconds a code stays valid. The standard is 30.
Algorithm
starts at SHA1 (standard)
SHA1 unless the service documents otherwise — authenticator apps all default to it.
SHA1 (standard)SHA256SHA512
Get your keys
What to click on the other service's side to get the values this block asks for. Paste each one in, then use “Save as credential” so it is encrypted and kept out of the workflow.
The authenticator setup key
You need: Access to the test account's two-factor settings.
1Sign in to the service as the test account and start setting up an authenticator app (two-factor / 2-step verification).
2When it shows the QR code, click the link under it — usually “Can't scan it?”, “Enter a setup key” or “Enter this text code instead”.
3Copy the key it reveals and paste it into Setup key (spaces are fine). An otpauth:// link, if the service offers one, works too.
4Also add the same key to an authenticator on your own phone, and finish the service's setup by typing the code it shows. Now both you and the workflow can sign in.
Looks like
JBSWY3DPEHPK3PXP (letters A–Z and digits 2–7, 16 to 32 of them)
⚠Two-factor already on and the key never written down? It cannot be shown again: turn two-factor off and on for the test account to get a new one.
⚠Use a test account. The key is as good as the second factor itself.
Build it
1
Paste the setup key
The base32 string the service showed next to the QR code when you set up the authenticator. An otpauth:// link works too, and its own digits and period win over the fields below.
2FA Code (TOTP)Settings
Setup keySave as credential · Required
write-only
Digits
6
Refresh every
30
Algorithm
SHA1 (standard)
2
Leave the three fields alone unless told otherwise
Six digits, thirty seconds, SHA1 is what every authenticator app defaults to. Change them only if the service documented something else.
what it produces
code418 209
valid forthe rest of this 30s window
3
Feed it to the code box
Put it immediately before the Input Text that types it. A code generated three steps early may have expired by the time it is typed.
2FA Code (TOTP)
Input Text — immediately after
What comes out
The current code, and how long it stays valid.
Watch out
⚠Typed into the node rather than saved as a credential, the key travels with the workflow — publishing the workflow publishes the second factor of that account.
⚠This is for test accounts. Do not point it at a real person's authenticator.
⚠Generate it late. The window is thirty seconds and a slow screen eats it.