Access Control
TOTP Verification
Every Studio account enrolls a TOTP authenticator. The same timing and replay rules apply to installation, invitation acceptance, recovery, factor replacement, sign-in, and protected account changes.
Fixed TOTP Parameters
The enrollment URI specifies HMAC-SHA-1, six decimal digits, and a 30-second period. Keep the authenticator device’s time automatically synchronized.
The issuer label uses the saved site title followed by · Studio, or the Studio hostname when a title is unavailable. Initial installation therefore uses the hostname. Changing the site title does not rename an entry already saved in an authenticator; the label is provided when enrolling the factor.
Adjacent Time-step Tolerance
For each request, Studio checks the previous, current, and next 30-second counter step. This handles a small clock difference or a code submitted near a boundary. It is a counter-step window, not a guaranteed lifetime from when someone reads the code.
A Counter Step Can Succeed Only Once
A successful verification atomically records the matched step. The factor’s next accepted code must belong to a strictly newer step.
- Resubmitting an already accepted code is rejected while it is still displayed.
- Concurrent reuse cannot complete a second verification.
- If a next-step code is accepted from an ahead-of-time authenticator, the current and older steps cannot subsequently succeed.
Incorrect, reused, and out-of-window codes return the same invalid-MFA result. The response does not disclose which check failed.
Enrollment Followed by Sign-in
Installation, activation, and factor replacement consume the submitted code. If the following sign-in screen asks for TOTP while that code remains visible, wait for the next code. The enrollment code cannot be reused.
Attempt Limits and Recovery
Enrolled TOTP verification shares an account-level attempt budget across sign-in and protected changes. Successful, incorrect, and replayed codes all consume it. See Authentication limits.
If a current-looking code fails, wait for the next code and check automatic time synchronization. A registered current-host Passkey can provide another sign-in method. If no factor is usable, follow MFA Recovery.