Skip to content

TOTP and authentication

Make shared account authentication part of managed access.

Time-based one-time passwords (TOTP) add an important protection to an account, but they can create a practical problem when a legitimate team needs to use a shared subscription. Subment keeps TOTP alongside the access it protects.

What TOTP is

TOTP is the short-lived code an authenticator app generates from a secret. It is commonly used as a second factor for sign-in. For a shared vendor account, sending the current code through chat creates a new copy of sensitive authentication information and no useful record of who requested it.

TOTP in Subment

A subscription’s TOTP secret is encrypted before storage. Someone with permission can ask Subment to generate the current code, with the same countdown an authenticator app shows. Recovery codes can be kept with the subscription too.

Generating a code requires a recent sign-in confirmation and is recorded with who and when, never with the secret or generated code. Verification codes delivered by email or SMS are a separate workflow and are not represented as TOTP.

Controlled workspace access

Workspace roles and subscription-level View, Use and Manage permissions control who can request authentication information. This is not an end-to-end encrypted or zero-knowledge design: Subment holds what it needs to generate a code for an authorized person. Learn more in Subment Security.

Bring the details and access together.

Subment is free during early access.

Get early access