What to provide
How to get the TOTP secret
When you set up MFA for the test account, most authenticators show a QR code and a text version of the secret key. Use the text version (a string of uppercase letters, e.g.JBSWY3DPEHPK3PXP).
If you’ve already set up MFA and don’t have the secret:
- Remove MFA from the test account
- Re-enroll and capture the secret this time
- Paste it into the authentication instructions
TOTP secrets are sensitive. They allow generating valid login codes at any time. Treat them like passwords and use only for dedicated test accounts.