> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/integrations/builtin/credentials/totp.md).

# Set up TOTP credentials in Duaer

Store TOTP connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
## Get the TOTP secret <a href="#get-the-totp-secret" id="get-the-totp-secret"></a>

The Duaer TOTP API credential stores the seed of a two-factor setup; the TOTP node turns it into a 6-digit code:

1. Turn on two-factor authentication in the service you sign in to. When the QR code appears, choose the option to show the key instead, copy the Base32 key such as BVDRSBXQB2ZEL5HE, and put it in Secret.
2. Label is optional, in issuer:username form, such as GitHub:john-doe.

This secret is a full second sign-in factor. Use it only in digital organizations that really need to sign in unattended, and share the credential only with people who must have it.

## TOTP API fields in Duaer <a href="#totp-api" id="totp-api"></a>

In Duaer, choose TOTP API when you create a credential, then fill in these fields:

- Secret (required, secret): Secret key encoded in the QR code during setup. Learn more (https://github.com/google/google-authenticator/wiki/Key-Uri-Format#secret).
- Label: Identifier for the TOTP account, in the issuer:username format. Learn more (https://github.com/google/google-authenticator/wiki/Key-Uri-Format#label).

Duaer nodes that use it: [TOTP](/integrations/builtin/core-nodes/duaer-nodes-base.totp.md).

## Save the connection in Duaer

Open Credentials and create TOTP. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys. The matching node is under [the related node](/integrations/builtin/core-nodes/duaer-nodes-base.totp.md).

## Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
## Questions

### Do TOTP secret values appear in Duaer node parameters?

No. In Duaer, TOTP secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

### What usually stops a TOTP credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields TOTP expects, then confirm you can create credentials in that project.

