TOTP codes
Rempar generates the time-based one-time codes (TOTP, RFC 6238) for services that require them. The secret lives in the vault, next to the password of the same account.
Adding a TOTP secret
On a Website or Mailbox item, tap Add a TOTP code, then:
- scan the QR code offered by the service, or
- paste the secret key (base32) shown by the service.
Rempar recognizes full otpauth:// URLs and reads the issuer, number of digits, period and algorithm from them.
Reading
The code is displayed grouped 3+3 in tabular figures. A 30-second ring empties in real time and turns orange under 6 seconds: wait for the next code if you are close to the limit. Copy places the code in the clipboard with the usual countdown.
Compatibility
Same standard as Google Authenticator. You can keep the same secret in both applications: the codes will be identical if the clocks are accurate. Rempar accepts SHA-1, SHA-256 and SHA-512, 6 or 8 digits, and periods from 15 to 120 seconds.
Should everything be kept in one place
A password and a TOTP code in the same vault reduce the second factor to "something you know" if the vault is open. In exchange, you gain an encrypted backup of your TOTP secrets and sync across devices. For your most sensitive accounts, keep the TOTP in a separate application, or in Rempar on a single device.
2FA for your Rempar account
The code that protects your own Cloud account must not be stored in the vault it protects. Keep it in Google Authenticator. See Google Authenticator 2FA.
A question not answered here? support@rempar.org