跳到主内容

Use the Casdoor Authenticator app

This guide explains how to install Casdoor Authenticator, connect it to your Casdoor instance, and move accounts from other authenticator apps into it.


Learning outcomes​

  • Install the app on Android or build it for iOS.
  • Connect the app to Casdoor and sync accounts.
  • Import accounts from Google Authenticator and Microsoft Authenticator.

What you need​

  • An Android or iOS device
  • To sync accounts: a Casdoor instance and an account on it

About Casdoor Authenticator​

Casdoor Authenticator is an open-source app (source code) for time-based one-time passwords (TOTP), like Google Authenticator and Microsoft Authenticator. It is a second factor for multi-factor authentication (MFA).

A TOTP code is computed from a secret that the app shares with the service and from the current time (RFC 6238). A code is valid for 30 seconds, and the app needs no network connection to generate it.

FeatureDescription
MFAGenerates TOTP codes for any service that supports them
Offline useGenerates codes without an internet connection
SyncSyncs accounts between devices through Casdoor
PrivacyEncrypts the stored data
AndroidiOS
androidios

Install the app​

Turn on account storage in Casdoor​

This step is optional. To store the TOTP accounts of the app in Casdoor, so that they sync between devices, add MFA accounts to the Account items of the organization in the Casdoor admin console.

MFA accounts setting in Casdoor

Connect the app to Casdoor​

Open the app and connect in one of three ways:

方法步骤
手动点击手动输入服务器,输入服务器URL、客户端ID和组织名称,然后登录。
二维码点击扫描二维码,扫描Casdoor服务器上我的账户→MFA账户中的二维码。
演示点击试用演示服务器以使用预配置的演示实例。

Connection options in the app

The app now shows your TOTP codes, and you can add and manage accounts.

Import accounts from another app​

Import from Google Authenticator​

  1. In Google Authenticator, open the menu and tap Transfer accounts.

  2. Select the accounts and tap Export. Google Authenticator shows a QR code.

    Export screen of Google Authenticator

  3. In Casdoor Authenticator, scan the QR code.

    Recording of the import from Google Authenticator

Import from Microsoft Authenticator​

This import works on Android only and needs root access, because the data of Microsoft Authenticator is in the private directory /data/data/com.azure.authenticator/databases/.

  1. On the device with Microsoft Authenticator, copy the PhoneFactor database file from that directory.

  2. In Casdoor Authenticator, open the import menu and tap Import from Microsoft Authenticator.

  3. Select the PhoneFactor file. 该应用会导入TOTP账户。

    Recording of the import from Microsoft Authenticator

See also​