iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To automate a TOTP login, generate a code from a test account’s shared secret in your test process, then enter it through the page’s normal form controls. Playwright and Puppeteer provide browser automation—not TOTP generation. Keep the secret and any saved authenticated browser state protected, and generate the code close to submission so it has not expired.
How TOTP fits into a browser test
TOTP is a time-based form of HOTP: the moving factor comes from time rather than a counter. The generator and the site’s verifier must agree on the secret and parameters, including the HMAC algorithm, number of digits, and time period. IETF RFC 6238 specifies a default time step of 30 seconds, but an application may configure a different period. That default is not a guarantee that every site accepts a code for exactly 30 seconds; the verifier’s configured acceptance window determines that. See RFC 6238.
The test flow is therefore two separate jobs: a TOTP implementation calculates a code, and the browser automation fills and submits it. Use a maintained library that supports the application’s settings, and validate its output against the RFC’s test vectors before relying on it in an end-to-end login test. The cited framework and standards documentation does not identify a universally preferred package.
Free tools Windows power users keep installed
One-click scans. No signup required.
How to handle TOTP in Playwright or Puppeteer
- Provision a controlled account. Use an account in a test environment and enroll a test-controlled TOTP secret through the application’s supported setup flow. Do not automate MFA against third-party accounts or use automation to evade access controls.
- Protect the secret. Keep the seed in protected CI configuration or a secret manager rather than source control. Restrict access to the test runner, and avoid exposing the seed or generated code in logs, screenshots, traces, or build artifacts.
- Configure the generator to match the application. Confirm the secret encoding, HMAC algorithm, digit count, and time period. Generate the code in the test process rather than expecting a browser helper to create it.
- Use ordinary browser interactions. Navigate to the login page, enter the username and password, wait for the OTP challenge, fill the current code, and submit. Assert an authenticated page condition; prefer explicit waits for UI conditions over fixed sleeps.
- Choose whether to repeat login or reuse state. Repeat login when the test needs to cover the MFA flow. For tests that do not need to exercise login, saved authenticated state may avoid repeating it, but that state is itself sensitive and does not test the login flow.
What Playwright and Puppeteer do—and do not—provide
Playwright
Playwright’s authentication guide describes saving browser state after login and reusing it in later tests; it is not a TOTP generator. The guide warns that the state file may contain cookies and headers that could impersonate an account. Store it in a protected, ignored location rather than committing it. Playwright also documents a virtual authenticator for WebAuthn credentials, which is distinct from TOTP. See Playwright authentication and Playwright WebAuthn virtual authenticator documentation.
#1 Best Overall
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Puppeteer
Puppeteer’s Page.authenticate() configures credentials for HTTP authentication; it does not enter a website’s TOTP challenge or generate a code. For a TOTP login, generate the OTP separately and interact with the page’s form. Puppeteer’s documentation notes that Page.authenticate() enables request interception behind the scenes, which may affect performance. The cited documentation displayed version 25.12.0; check the documentation for the version used by your project. See Puppeteer Page.authenticate().
Repeat login or reuse authenticated browser state?
| Approach | Useful when | Trade-off |
|---|---|---|
| Repeat login with TOTP | The test must exercise the MFA challenge and login flow. | Requires a controlled test account, a correctly configured secret, and code generation timed near submission. |
| Reuse authenticated browser state | The test focuses on behavior after login and does not need to cover authentication. | State files can contain impersonation-capable cookies or headers, so they need credential-level protection; the test does not verify the login flow. |
Playwright recommends saved state for suitable tests, while noting that sharing accounts can be unsuitable when tests mutate server-side state or require browser-specific authentication. See Playwright’s authentication guidance.
Rank #2
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
How to prevent expired-code failures
Code age matters because generation, navigation, and UI waits all consume time. Generate the OTP near the point of use, keep the test runner’s clock synchronized, and make the site’s acceptance window authoritative for that environment. RFC 6238’s 30-second default describes the time step, not a universal verifier window. RFC 6238 also identifies clock drift and network delay as considerations for validation; the application’s configuration governs the actual test behavior.
Recommended Free Tools
- Confirm the generator uses the same secret encoding and parameters as the enrolled account.
- Check the runner’s clock and the age of the code when it is submitted.
- Check whether account lockouts or rate limits are being triggered.
- Ensure concurrent tests are not sharing an account or attempting to use the same code.
- Keep production verification settings intact; resolve timing issues with controlled test accounts and environment-specific configuration, not weakened production MFA.
Keep TOTP and browser state secure
RFC 6238 requires a unique secret for each prover and says keys must be protected against unauthorized access and use. NIST’s SP 800-63-4 guidance states that OTP authentication is not phishing-resistant and addresses protected secrets, defined TOTP validity, replay resistance, and rate limiting. These are verifier and account-design responsibilities; browser tests should use the supported flow rather than bypassing them. See NIST SP 800-63-4, authenticator guidance and RFC 6238.
Rank #3
- Ultra-Compact FIDO2 Security Key – Plug-and-stay or carry on a keychain. This USB-C hardware security key offers portable, always-on protection for desktop and mobile use.(Item Size: 0.73 X 0.60 X 0.30 inches)
- USB-C Hardware Key for All Devices – Works with USB-C ports on PC, Mac, Android, and USB-C iPhones. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key – Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey – Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication – Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Treat saved browser state as a credential as well as the TOTP seed. Limit access to both, keep them out of version control and diagnostics, and rotate or reset test credentials through the application’s test-account process. Make CI artifact retention and access controls account for screenshots, traces, and other outputs that could reveal authentication data.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When the application uses passkeys instead
Use a test mechanism that matches the application’s actual second factor. TOTP uses a shared secret and time-derived one-time codes. WebAuthn/passkeys use credential ceremonies; Playwright’s virtual authenticator is intended for that WebAuthn flow, not for generating TOTP codes. See Playwright’s virtual authenticator documentation and RFC 6238.
Quick Recap
Best Value
- FIDO2/Passkey Authentication – Secure, passwordless login with supported platforms. Check if your intended service supports hardware keys before purchase. Works with Gmail, Facebook, GitHub, Dropbox, and more.
- Enhanced Multi-Factor Authentication (MFA): Strengthen account security using either FIDO2.0 authentication or TOTP/HOTP codes, providing flexible options for added protection.
- Universal Connectivity: Features USB-A and NFC compatibility, making it easy to use across various devices including PCs, Macs, iPhones, and Android phones for seamless integration.
- Durable & Portable Design: Built with a 360° rotating metal cover for extra durability. Compact and lightweight, it easily attaches to a keychain for on-the-go convenience. No batteries or network required, ensuring dependable use anywhere.
- FIDO Certified & Business-Ready: Certified for FIDO standards and supported by a range of management software suites, ideal for both individual users and enterprise deployment.
Rank #4
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors

