Set up MultiMFA TOTP to share authenticator app codes with approved viewers, QR enrollment, access reviews, offboarding, and secure team workflows.
Best for: Teams that share app-based MFA across multiple people.
Overview
MultiMFA TOTP lets a manager add TOTP apps in two ways (paste secure code or scan QR) and invite viewers to a read-only authenticator-style dashboard for shared codes.
Finding this in the dashboard
Click MultiMFA TOTP in the dashboard sidebar. Overview and Share MFA Codes also open this workspace. Naming, app import, viewers, and TOTP activity all stay on this one page.
Step-by-step setup
Step 1
Open MultiMFA TOTP
After you log in, click MultiMFA TOTP in the dashboard sidebar. You can also start from Share MFA Codes and choose MultiMFA App Code (TOTP).
Step 2
Purchase a license
Start a free trial or choose a paid TOTP plan on the MultiMFA TOTP page.
Step 3
Add an app
Scan a QR code or paste a setup key to add the authenticator entry you want to share. Choose one complete method below.
Choose your setup workflow
Follow one complete method from start to finish. You do not need to do both.
Method A: Paste secure code
Use this when the service provides a raw setup key or secret code you can copy.
1.In the external service 2FA setup, choose the option to show the setup key/secret text.
2.Copy the full secret code exactly as shown.
3.In MultiMFA TOTP, choose manual setup and paste the secure code into the app form.
4.Save the app, then verify one generated 6-digit code in the external service.
Method B: Scan QR code
Use this when the service shows a QR code and you prefer camera-based capture.
1.In MultiMFA TOTP, choose QR setup for the new app.
2.If the QR is on desktop, send the secure scan link to yourself by SMS or email.
3.Open the scan link on your phone to launch mobile capture.
4.Point your phone at the QR code and let MultiMFA capture it automatically.
5.Save the app, then verify one generated 6-digit code in the external service.
Step 4
Add viewer users
On the same MultiMFA TOTP page, invite the people who should see the shared rotating codes. They receive an invite to create or complete their account.
Step 5
Complete viewer onboarding and daily access
Invitees accept terms, set a password, and log in to a read-only viewer dashboard showing current shared codes.
Step 6
Maintain app and access hygiene
Rotate app secrets when required and remove viewer access when someone no longer needs it.
Best practices
•Create clear license and app labels (for example "AWS Root Prod").
•Use paste method when you have the raw secret key available.
•Use QR method when secret key text is hidden or hard to copy.
•Use the send-link flow whenever QR is displayed on another device.
•Always open the scan link on the phone that will capture the QR.
•Grant viewer access by least privilege only.
•Audit shared app access after personnel changes.
•Rotate sensitive TOTP secrets on a defined schedule.
Common troubleshooting
•If the scan link does not arrive, retry with the other channel (SMS vs email) and confirm contact details.
•If phone capture does not start, open the link directly on mobile instead of desktop.
•If QR capture fails, increase screen brightness on the device showing the QR and retry.
•If you cannot scan QR, switch to manual paste by using the service "enter setup key manually" option.
•If a code fails, confirm time sync on the external service and retry on the next 30-second window.
•If viewers cannot log in, resend invite and verify email ownership.
•If an app is missing for a viewer, check the share assignment in manager settings.