Skip to main content
Templates
Auth

Automate MFA with Vaults

Store username, password, and a TOTP secret in a Notte Vault so browser sessions can complete MFA without manual input.

Last updated

Run this template

Clone just this template, configure Notte, and start the run.

Before running

Credential flow

  • Vault setup: opens the demo page, extracts the test credentials and TOTP secret, and saves them to an ephemeral Notte vault.
  • Automatic TOTP filling: uses vault placeholders in a form fill action; Notte generates the current TOTP code from the stored secret.
  • Retry logic: reloads the page and fills from the vault again if the first TOTP window expires.
  • Initializes a Notte browser session.

Secrets and state

  • session.page: use Playwright primitives through a Notte browser session.
  • scrape: extract structured data from web pages using natural language instructions and Pydantic models.
  • Vault: encrypted Notte credential storage attached to a browser session with vault_id.
  • mfa_secret: a stored TOTP secret key. The vault turns it into a fresh one-time code when the fill action uses the MFA placeholder.

Where to adapt it

  • Vault-backed MFA: Store encrypted TOTP secrets alongside username and password credentials.
  • Automated authentication: Complete MFA challenges automatically when session persistence isn't enough.
  • Zero-touch MFA: Eliminate user interaction for MFA completion in automated workflows.
  • Session recovery: Automatically handle MFA prompts when re-authenticating expired sessions.

Frequently asked questions

How do I automate MFA login for an AI agent without manual codes?

Store the username, the password and the TOTP secret in a Notte Vault, attach the vault to the browser session, and use vault placeholders in the form fill action. Notte generates the current one-time code from the stored secret at fill time, so nobody has to type a code.

How do AI agents handle 2FA and MFA?

What happens if the one-time code expires while the form is being filled?

The template reloads the page and fills from the vault again, which produces a fresh code for the new TOTP window.

Which kinds of MFA does this template cover?

Authenticator-app codes (TOTP), where the site gives you a secret key at enrollment. For sign-in links and codes sent by email, use a Notte Persona mailbox instead.

Receive auth emails with Personas template

Is the TOTP secret hardcoded in my script?

No. The secret is saved in the vault, which is encrypted Notte credential storage attached to the session with vault_id. The script only references a placeholder.

What is credential vaulting for AI agents?