OTP (One-Time Password)
OTP (One-Time Password) is a time-based dynamic verification method. A new 6-digit code is generated every 30 seconds to add extra security to your account.
Tip
Enabling OTP 2FA is recommended for all users, especially administrators.
Supported authenticator apps: Google Authenticator, Microsoft Authenticator, Authy, 1Password, etc.
Features
- Time-based sync: RFC 6238 TOTP standard
- High security: code refreshes every 30 seconds
- Offline availability: no network required to generate codes
- Multi-device support: can be configured on multiple devices
Enable OTP
1. Open Personal Center
After login, click username and go to Personal Center.
2. Enable OTP
Find OTP Two-Factor Authentication.
3. Scan QR code
Use authenticator app on your phone:
- Open authenticator app (for example Google Authenticator)
- Click Add account /
+ - Select Scan QR code
- Scan the code shown on screen
4. Manually enter secret (alternative)
If QR scanning is unavailable:
- Choose Manual entry in app
- Enter the displayed secret key
- Set account name (service name recommended)
5. Verify setup
Enter the 6-digit code generated by app and click Confirm.
Login Flow
After OTP is enabled:
- Enter username and password
- Open authenticator app
- Find the account item
- Enter current 6-digit code
- Click login
Note
- OTP code refreshes every 30 seconds
- If current code is close to expiration, wait for the next one
- Each code can only be used once
Backup and Recovery
Recovery codes
A set of recovery codes is generated when enabling OTP. Keep them safe:
- Download and print recovery codes
- Store them in a safe place
- Do not keep recovery codes only on your phone
Use recovery code
If OTP code is unavailable:
- Click Use recovery code on login page
- Enter any unused recovery code
- After login, reconfigure OTP as soon as possible
FAQ
Q: Why is verification code always invalid?
A:
- Ensure device time is synced correctly
- Ensure code has not expired
- Use the currently displayed code
- Do not reuse the same code multiple times
Q: What if phone is lost or damaged?
A:
- Use saved recovery code to log in
- Ask administrator to reset OTP
- Set up OTP again
Q: Can OTP be configured on multiple devices?
A: Yes. Scan the same QR code or use the same secret key on multiple devices.
Q: How to disable OTP?
A: Go to personal settings, find OTP option, click Disable.
Best Practices
- Backup regularly: verify recovery codes are still safely stored
- Use multiple devices: avoid single-device failure
- Keep time accurate: prevent verification failures due to time drift
- Store secrets securely: prevent leakage
Security recommendations
- Do not enter OTP codes in public unsafe environments
- Do not screenshot QR code or secret key
- Keep authenticator app updated
- If suspicious login is detected, change password and reset OTP immediately