Knowledge Base
Browse the concepts behind Truestamp. Follow the links between concepts, or search across everything.
Tagged: totp
4
Accounts
Signing In to Truestamp
How you authenticate to Truestamp - password sign-in throttled against brute force, passwordless magic-link sign-in, one-step passkey sign-in, an optional TOTP second factor with throttled recovery codes, the limits on account emails, and how a session is established and ended.
Two-Factor Authentication and Recovery Codes
How Truestamp two-factor authentication works - authenticator-app (TOTP) enrollment and verification, single-use recovery codes, and the per-account brute-force rate limits on TOTP and recovery-code entry.
Glossary
Recovery code
A single-use backup code issued in a batch when Truestamp two-factor authentication is enrolled, entered in place of a TOTP code at the second-factor step; each code works exactly once, only a hashed form is stored, and regenerating a batch invalidates the previous one.
TOTP
Time-based One-Time Password, the optional authenticator-app second factor on a Truestamp account; after a password or magic-link sign-in you enter the app's rotating six-digit code, with code entry rate-limited to 3 attempts per 5-minute window against brute-force guessing.