---
description: Studio TOTP parameters, enrollment labels, adjacent-step tolerance, and replay protection.
---

# TOTP Verification

Every Studio account enrolls a TOTP authenticator. The same timing and replay
rules apply to installation, invitation acceptance, recovery, factor replacement,
sign-in, and protected account changes.

## Fixed TOTP Parameters

The enrollment URI specifies HMAC-SHA-1, six decimal digits, and a 30-second
period. Keep the authenticator device's time automatically synchronized.

The issuer label uses the saved site title followed by `· Studio`, or the
Studio hostname when a title is unavailable. Initial installation therefore
uses the hostname. Changing the site title does not rename an entry already
saved in an authenticator; the label is provided when enrolling the factor.

## Adjacent Time-step Tolerance

For each request, Studio checks the previous, current, and next 30-second
counter step. This handles a small clock difference or a code submitted near
a boundary. It is a counter-step window, not a guaranteed lifetime from when
someone reads the code.

## A Counter Step Can Succeed Only Once

A successful verification atomically records the matched step. The factor's
next accepted code must belong to a strictly newer step.

- Resubmitting an already accepted code is rejected while it is still displayed.
- Concurrent reuse cannot complete a second verification.
- If a next-step code is accepted from an ahead-of-time authenticator, the
  current and older steps cannot subsequently succeed.

Incorrect, reused, and out-of-window codes return the same invalid-MFA result.
The response does not disclose which check failed.

## Enrollment Followed by Sign-in

Installation, activation, and factor replacement consume the submitted code.
If the following sign-in screen asks for TOTP while that code remains visible,
wait for the next code. The enrollment code cannot be reused.

## Attempt Limits and Recovery

Enrolled TOTP verification shares an account-level attempt budget across
sign-in and protected changes. Successful, incorrect, and replayed codes all
consume it. See [Authentication limits](../authentication/index.md#attempt-limits).

If a current-looking code fails, wait for the next code and check automatic
time synchronization. A registered current-host Passkey can provide another
sign-in method. If no factor is usable, follow
[MFA Recovery](../mfa-recovery/index.md).
