TOTP

Time-based one-time passwords for two-factor login. A member pairs an authenticator app once, then each login needs the rotating code along with their password.

Two-factor authentication is table stakes for admin accounts, and members with money on the line deserve the same protection: course buyers, community members, anyone whose account is a target for resale or hijacking. TOTP is the industry-standard second factor: a six-digit code from an authenticator app that changes every 30 seconds. It works with every authenticator on the market, from Google Authenticator to 1Password to a YubiKey's companion app, and it needs no phone number, no SMS gateway, and no per-message fees.

Setup is a QR code. The member visits [memb_totp_setup], scans the code with their app, and confirms one generated code to prove the pairing took. From then on, login asks for the password and the current code. [memb_totp_verify] and [memb_totp_manage] round out the flow for verifying codes in custom login forms and for removing or re-pairing a device.

The member-facing setup screen: a QR code, a manual entry key, and a field for the first six-digit code

Recovery is a scratch code generated at pairing time. A member who loses their phone uses the code once to get in, then pairs the new phone. Members who never opt in are unaffected: TOTP is per member, so it hardens the accounts that need it without forcing it on a casual visitor.

Admin screens

The module's settings live at Membership → TOTP 2FA (or via the TOTP card on the Control Center). The issuer name, time window, and recovery-code count are described in Setting Up Login Security; the screen also shows enrollment counts and a delete-all control for clearing every member's TOTP data at once. The Enforcement card on the same screen requires two-factor for the roles you choose, with a grace period for each member: see 2FA Enforcement.

The TOTP settings screen: issuer name, time window, recovery code count, and enrollment statistics

Two admin views show you where enrollment stands without opening anyone's profile. The Users list has a 2FA column with a green or red icon per account:

The WordPress Users list showing the 2FA column with red inactive icons

And each member's Member Profile screen has a TOTP section with status, last-used time, and remaining recovery codes, plus a Delete TOTP Setup button for helping a locked-out member start over:

The TOTP section of the member profile screen, showing status, last used, and recovery codes remaining

Articles

Shortcodes

ShortcodeWhat it does
[memb_totp_manage] Renders the two-factor authentication management panel: status, usage, disable, and recovery-code regeneration.
[memb_totp_setup] Renders the two-factor authentication enrollment flow: QR code scanning and first-code verification.
[memb_totp_verify] Renders the two-factor verification form shown after password login for TOTP-enabled accounts.