CodeLogic.TwoFactorAuth
4.5.2-preview.68
See the version list below for details.
dotnet add package CodeLogic.TwoFactorAuth --version 4.5.2-preview.68
NuGet\Install-Package CodeLogic.TwoFactorAuth -Version 4.5.2-preview.68
<PackageReference Include="CodeLogic.TwoFactorAuth" Version="4.5.2-preview.68" />
<PackageVersion Include="CodeLogic.TwoFactorAuth" Version="4.5.2-preview.68" />
<PackageReference Include="CodeLogic.TwoFactorAuth" />
paket add CodeLogic.TwoFactorAuth --version 4.5.2-preview.68
#r "nuget: CodeLogic.TwoFactorAuth, 4.5.2-preview.68"
#:package CodeLogic.TwoFactorAuth@4.5.2-preview.68
#addin nuget:?package=CodeLogic.TwoFactorAuth&version=4.5.2-preview.68&prerelease
#tool nuget:?package=CodeLogic.TwoFactorAuth&version=4.5.2-preview.68&prerelease
CodeLogic.TwoFactorAuth
TOTP two-factor authentication with QR code generation for CodeLogic applications.
Install
dotnet add package CodeLogic.TwoFactorAuth
Quick Start
var tfaLib = new TwoFactorAuthLibrary();
// After library initialization via the CodeLogic framework:
// Generate a new key bound to an issuer + user (creates a fresh Base32 secret)
TwoFactorKey key = tfaLib.GenerateNewKey("MyApp", "user@example.com");
// Persist key.SecretKey alongside the user record for later validation
// Render a QR code as a data URI for an authenticator app (Google Authenticator / Authy / 1Password)
Result<string> qrDataUri = tfaLib.GenerateQrCodeDataUri(key);
if (qrDataUri.IsSuccess)
{
// Embed qrDataUri.Value in an <img src="..."> tag
}
// Validate a code entered by the user
TotpValidationResult result = tfaLib.ValidateTotp("123456", key.SecretKey);
Console.WriteLine($"Valid: {result.IsValid}");
Features
- Secret key generation — cryptographically random Base32-encoded TOTP secrets (
GenerateSecretKey) - Provisioning keys —
GenerateNewKey(issuer, user)returns aTwoFactorKeyexposing a standardotpauth://ProvisioningUri - TOTP generation & validation —
GenerateTotpCodeandValidateTotpwith configurable time-step and drift window; validation returns aTotpValidationResult(including the matched window offset) - Code lifetime helpers —
GetSecondsUntilExpiry()andGetCurrentTimeWindow() - QR code rendering — PNG bytes, BMP bytes, Base64, data URI, and save-to-file output with configurable module size and error-correction level
- Google Authenticator compatible — standard
otpauth://totp/...URI format (RFC 6238) - Event integration —
SecretKeyGeneratedEventandTotpValidatedEventare published to the CodeLogic event bus - Health check — exercises live TOTP key generation
Services
The library exposes two services plus convenience pass-throughs:
| Member | Returns | Purpose |
|---|---|---|
Authenticator |
TwoFactorAuthenticator |
TOTP generation/validation service |
QrCode |
QrCodeGenerator |
QR code rendering service |
GenerateSecretKey() |
string |
New Base32 secret |
GenerateNewKey(issuer, user) |
TwoFactorKey |
New key + provisioning URI |
ValidateTotp(code, secretKey) |
TotpValidationResult |
Verify a 6-digit code |
GenerateQrCodeDataUri(key) |
Result<string> |
data:image/png;base64,... URI |
TwoFactorAuthenticator
var auth = tfaLib.Authenticator;
string secret = auth.GenerateSecretKey();
Result<string> codeResult = auth.GenerateTotpCode(secret);
// userId is optional — when supplied, a TotpValidatedEvent is published
TotpValidationResult check = auth.ValidateTotp("123456", secret, userId: "alice");
int secondsLeft = auth.GetSecondsUntilExpiry();
long window = auth.GetCurrentTimeWindow();
QrCodeGenerator
var qr = tfaLib.QrCode;
var key = tfaLib.GenerateNewKey("MyApp", "user@example.com");
Result<byte[]> png = qr.GenerateQrCodePng(key);
Result<byte[]> bmp = qr.GenerateQrCodeBmp(key);
Result<string> base64 = qr.GenerateQrCodeBase64(key);
Result<string> uri = qr.GenerateQrCodeDataUri(key);
Result saved = qr.SaveQrCodeToFile(key, "qrcode.png");
Configuration
Config file: config.twofactorauth.json
{
"Enabled": true,
"TimeStepSeconds": 30,
"WindowSize": 1,
"QrCodeModuleSize": 20,
"ErrorCorrectionLevel": "Q"
}
| Setting | Default | Description |
|---|---|---|
Enabled |
true |
Master switch; when false the services are not created and the health check reports disabled |
TimeStepSeconds |
30 |
TOTP time step in seconds (1–300); must match the authenticator app |
WindowSize |
1 |
Steps before/after the current window to accept (0–10); 1 ≈ ±30s drift tolerance |
QrCodeModuleSize |
20 |
Pixel size of each QR module (1–100) |
ErrorCorrectionLevel |
Q |
QR error correction: L (~7%), M (~15%), Q (~25%), H (~30%) |
Documentation
Full API docs: https://github.com/Media2A/CodeLogic.Libs
Requirements
- .NET 10.0+
- CodeLogic 3.x or 4.x
- Otp.NET 1.x
- QRCoder 1.x
License
MIT — see LICENSE
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.6.72 | 178 | 6/20/2026 |
| 4.6.69-preview | 36 | 6/20/2026 |
| 4.5.2 | 105 | 5/24/2026 |
| 4.5.2-preview.68 | 57 | 6/20/2026 |
| 4.5.1 | 157 | 5/24/2026 |
| 4.5.1-preview.56 | 97 | 5/24/2026 |
| 4.4.2-preview.53 | 56 | 5/24/2026 |
| 4.4.1 | 101 | 5/24/2026 |
| 4.0.5 | 107 | 5/15/2026 |
| 4.0.4 | 111 | 5/9/2026 |
| 4.0.3 | 109 | 5/9/2026 |
| 3.3.1 | 624 | 4/18/2026 |
| 3.3.0 | 114 | 4/18/2026 |
| 3.2.11 | 125 | 4/18/2026 |
| 3.2.10 | 113 | 4/18/2026 |
| 3.2.9 | 108 | 4/18/2026 |
| 3.2.8 | 107 | 4/18/2026 |
| 3.2.7 | 107 | 4/18/2026 |
| 3.2.6 | 107 | 4/18/2026 |
| 3.2.5 | 114 | 4/18/2026 |
# CL.TwoFactorAuth — Changelog
All notable changes to **CodeLogic.TwoFactorAuth** are documented here. Versions follow
[Semantic Versioning](https://semver.org/).
## [4.5.2] — 2026-06-20
### Documentation
- Corrected the README and the security guide to match the shipping API. The
previous docs referenced members and config keys that do not exist
(`GenerateSecret`, `Validate(secret, token)`, `GetOtpAuthUri`, backup-code
helpers, and the `Issuer`/`SecretKeyLength`/`TokenValiditySeconds`/
`AllowedClockSkewSeconds`/`QrCodeSize` settings).
- Documented the real configuration keys: `Enabled`, `TimeStepSeconds`,
`WindowSize`, `QrCodeModuleSize`, and `ErrorCorrectionLevel`
(`L`/`M`/`Q`/`H`).
- Documented the `Authenticator` and `QrCode` services and their full surface:
`GenerateSecretKey`, `GenerateNewKey`, `GenerateTotpCode`, `ValidateTotp`
(incl. the optional `userId` argument and the `TotpValidationResult` shape),
`GetSecondsUntilExpiry`, `GetCurrentTimeWindow`, and the QR outputs
`GenerateQrCodePng` / `GenerateQrCodeBmp` / `GenerateQrCodeBase64` /
`GenerateQrCodeDataUri` / `SaveQrCodeToFile`.
- Documented the `TwoFactorKey.ProvisioningUri` (`otpauth://`) property, the
`SecretKeyGeneratedEvent` / `TotpValidatedEvent` bus events, and the actual
health-check behavior (live TOTP key generation).
## [4.5.0] — 2026-05-24
### Changed
- **Unified versioning.** All CodeLogic.Libs now share a single version line
controlled by `version.txt` in the repo root. This is a version alignment
release — no functional changes to this library.
## [4.0.4] — 2026-04-16
### Changed
- README + manifest refresh for the v4 baseline. No functional changes vs 4.0.3.
- `LibraryManifest.Version` now reads from assembly metadata.
## [4.0.2] — 2026-04-09
### Changed
- Annotated 2FA configuration with `[ConfigField]` for the admin UI surface.
- Aligned with the v4 baseline across all libraries.
## [4.0.0] — 2026-04-09
Major rewrite. Republished as v4.0.0 to reset the version line under the
unified v4 baseline. TOTP-based 2FA with QR code generation, backup codes,
and a CodeLogic-native flow for Google Authenticator / Authy / 1Password.
### Notes
- Earlier history is retained in the
[git log](https://github.com/Media2A/CodeLogic.Libs/commits/main/CL.TwoFactorAuth).