Skip to content

TOTP.generateOTP() ​

Generates a Time-based One-Time Password (TOTP) from a Base32 shared secret key.

This command is provided by the built-in totp plugin and allows automated tests to solve Two-Factor Authentication (2FA) and Multi-Factor Authentication (MFA) challenges for login flows (e.g. Google, GitHub, AWS, Salesforce, Okta).

Load the Plugin

The totp plugin must be loaded in your test script before calling generateOTP():

js
let totp = TEST.loadPlugin("totp")

Usage ​

js
// 1. Generate with default settings (6 digits, 30s period, SHA-1)
let code = totp.generateOTP(key)

// 2. Specify digit length directly
let code = totp.generateOTP(key, digits)

// 3. Pass custom options object
let code = totp.generateOTP(key, options)

// 4. Pass key inside options object
let code = totp.generateOTP(options)

Parameters ​

ParameterTypeDescription
keystringRequired.
The Base32 shared secret key provided during 2FA authenticator setup (e.g. JBSWY3DPEHPK3PXP). Whitespaces are automatically stripped and letter casing is normalized.
digitsnumberOptional shortcut to specify the code length (typically 6 or 8). Default is 6.
optionsobjectOptional configuration object (see below).

Options Object ​

OptionTypeDefaultDescription
keystring—The Base32 secret key (when passing options as a single object).
digitsnumber6Length of the generated OTP code (usually 6 or 8).
periodnumber30Time step window in seconds (usually 30 or 60).
algorithmstring"SHA-1"Hash algorithm. Supported values: "SHA-1", "SHA-256", "SHA-512".
timestampnumberDate.now()Optional custom epoch timestamp in milliseconds for testing token generation.

Return Value ​

TypeDescription
stringThe generated numeric OTP string (e.g. "491823").

Behavior ​

  • Automatic Formatting: Whitespaces in the secret key are automatically removed and characters are converted to uppercase.
  • Smart Expiration Protection: If fewer than 10 seconds remain in the current time window, the plugin automatically pauses and waits for the next cycle to start. This ensures that the generated code does not expire while the browser is submitting the form.
  • Test Report Logging: The command logs to the test report in the format Generate OTP: 491823 (Valid for 24s). Screenshot capture is disabled for this command.

Examples ​

Basic 6-Digit OTP ​

js
let totp = TEST.loadPlugin("totp")

// Generate code using a secret key stored in project variables
let code = totp.generateOTP(DATA.totp_secret)

// Fill into the 2FA form
I.fill("Verification code", code)
I.click("Verify")

Custom 8-Digit Code with SHA-512 ​

js
let totp = TEST.loadPlugin("totp")

let code = totp.generateOTP(DATA.totp_secret, {
    digits: 8,
    period: 60,
    algorithm: "SHA-512"
})

I.fill("code", code)
I.click("Submit")

Conditional 2FA Login Flow ​

js
// Login with primary credentials
I.goTo("https://example.com/login")
I.fill("Username", DATA.username)
I.fill("Password", DATA.password)
I.click("Log In")

// Only solve 2FA challenge if prompted
if (I.see$("Enter 2-step verification code")) {
    let totp = TEST.loadPlugin("totp")
    let code = totp.generateOTP(DATA.totp_secret)

    I.fill("Security code", code)
    I.click("Verify")
}

I.see("Dashboard")

Error Suppression and Silent Mode ​

  • totp.generateOTP(): Standard execution. Logs the generated OTP step to the test report and throws an error if the key is missing or invalid.
  • totp.generateOTP$(): Error suppression mode. If an error occurs (e.g. invalid Base32 key), execution continues without failing the test.
  • totp.generateOTP$$(): Silent mode. Suppresses errors and hides the command step from the test report.

See Also ​