NewOIDC SSO and SCIM provisioning for enterprise rollout

Share 2FA codes securely across your team.

Share and govern TOTP access without screenshots, spreadsheets, or shadow IT. Built for ops, finance, and admin teams that need speed, accountability, and identity-managed access.

Centralized access

One workspace for all shared 2FA secrets, with role-based controls.

Faster workflows

Request, approve, and revoke access in minutes.

Audit-ready

Immutable logs for who accessed what and when.

Reduced risk

No more forwarding codes over chat or email.

Security-first by design.

Secrets are encrypted at rest and in transit.

Access is governed by roles and explicit permissions.

Every action is logged for compliance and incident response.

Enterprise identity

Connect shared 2FA to your source of truth.

Keep ShareOTP aligned with your identity provider while preserving account-level control over every shared TOTP code.

OIDC SSO

Route workspace users through your identity provider with Optional and Required SSO modes.

SCIM provisioning

Create, update, and deprovision users from your workforce directory using SCIM 2.0.

Domain-based rollout

Use approved email domains for JIT provisioning and smooth migration from password sign-in.

Review setup details in the identity management documentation or configure provisioning with the SCIM setup guide.

Easiest way to share 2FA codes with your team

Securely share 2FA tokens with teammates without friction, extra steps, or IT overhead.

Assign access and share accounts with the right people only.

Centralize access with OIDC SSO, SCIM provisioning, and admin-controlled account permissions.

Reduce seed exposure by allowing users to access generated 2FA codes without revealing the seed.

Shared TOTP accounts vault interface
See how these capabilities map to real teams in our 2FA guide for technology companies and access model for development agencies, or review implementation details in the ShareOTP product documentation.

Web-based - no app required

Access and approve 2FA codes from any web browser on desktop or mobile. No separate phone or dedicated app needed.

Every access event, fully logged.

Immutable audit trails show who viewed which code and when - ready for compliance and incident response.

Filter by actor, event, or account to pinpoint sensitive activity fast.

Admin / Audit log

Audit log

Track sensitive actions across your workspace.

TimeActorEventEntityIP
Feb 3, 9:12 AM
Security admin
VIEWED
AWS Root
ACCOUNT - 1-4f2a
34.82.12.0
Feb 3, 8:41 AM
Workspace admin
GRANTED
Stripe Ops -> [email protected]
PERMISSION - 2-b1a9
18.206.122.9
Feb 3, 8:05 AM
On-call engineer
REVOKED
GitHub Prod -> [email protected]
PERMISSION - 2-c3d4
52.14.88.31
Feb 2, 6:19 PM
system
Automated policy
ROTATED
Okta Admin
ACCOUNT - 1-9e7c
-
Explore audit workflows for IT consulting teams handling client admin access and integrate events through the ShareOTP audit API documentation.

Frequently asked questions