Authenticator Apps (TOTP) Settings

Customize your Authenticator Apps (TOTP) authentication from the Descope console (Settings > Authentication Methods > Authenticator Apps (TOTP)).

Enable Method in API and SDK

The Enable method in API and SDK toggle controls whether Authenticator Apps (TOTP) authentication can be invoked programmatically via APIs and SDKs.

  • When enabled: Authentication works via flows, APIs, and SDKs
  • When disabled: Authentication only works with flows or calls made with a valid management key

Customizing the Authenticator App Label

By default, the entry Descope creates in a user's authenticator app (Google Authenticator, Authy, etc.) is labeled with your project's name. If you want your own brand name to appear instead, set a custom Authenticator service label.

This controls the label the authenticator app stores when a user enrolls in TOTP. Changing it does not update existing enrollments, which keep the label they were created with until the user re-enrolls. For example, if your project is called "Descope" but you want the authenticator app to show "MyApp", set the Authenticator service label to "MyApp".

Note

The label can also be set using dynamic values.

You can set this from the same Console page, or programmatically with the Get TOTP Settings and Set TOTP Settings Management API calls (issuerLabelTemplate field).

Replay Protection

Once a TOTP code has been used to sign in or enroll, Descope rejects that same code if it's submitted again within its validity window (an authenticator app code typically refreshes every 30 seconds), instead of allowing a second use. This prevents an intercepted code from being replayed while the legitimate user is still signing in.

A rejected replay is logged as a TOTPCodeReused audit event and returns error E061105 instead of the generic invalid-code error.

Was this helpful?

On this page