---
title: "Create a one-time authentication secret and code"
method: GET
path: "/twofactorauth_generate_tfa_config"
tags: ["Authentication", "Two-Factor Authentication"]
---

# Create a one-time authentication secret and code

`GET /twofactorauth_generate_tfa_config`

This function generates a random secret and a one-time password authentication (OTP auth) URL for the user. Use the secret that this function returns and a valid verification token with WHM API 1's `twofactorauth_set_tfa_config` function to configure Two-Factor Authentication (2FA) on an account.

## Response `200`

HTTP Request was successful.

- object
  - `data` object
    - `otpauth_str` string, uri — A one-time authentication URL to encode as the QR code.
    - `secret` string — A generated security code for use with 2FA.
  - `metadata` object
    - `command` string — The method name called.
    - `reason` string — The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds.
    - `result` 0 | 1 — * `1` — Success. * `0` — Failed. Check the `reason` field for more details.
    - `version` integer — The version of the API function.

---

[API](https://skmtc.net/cpanel/apis/whm-api.md) · [All operations](https://skmtc.net/cpanel/apis/whm-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/cpanel/whm-api/revisions/3da41671c02c/schema)
