A Heroku account deploys code, holds config vars full of API keys and database credentials, and runs up the bill — exactly what attackers look for. That is why Salesforce requires multi-factor authentication of every Heroku user. Salesforce Authenticator is one way to meet it; a time-based code from any authenticator app is another, and it needs no phone signal.
Add an authenticator app to Heroku
New Heroku accounts are asked to turn on multi-factor authentication as they are created — then the setup opens on its own, and you pick the one-time password generator there. If your team signs in to Heroku through single sign-on, multi-factor authentication is set up at that identity provider instead, and these steps do not apply.
- Sign in to the Heroku Dashboard on your computer.
- Open “Account Settings”.
- Select “Setup Multi-Factor Authentication” — or “Manage Multi-Factor Authentication” if a verification method is already on.
- Click “Add One Time Password Generator”.
- Heroku shows a QR code. Leave it on the screen and add it to the extension as described below — then enter the code from the extension and click “Connect”.
Add Heroku to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Heroku page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Heroku and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Heroku confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Heroku’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeGenerate your 10 Heroku recovery codes
Recovery codes are a verification method of their own: on the same multi-factor authentication page choose “Add Recovery Codes”, and Heroku shows 10 single-use codes. Save them somewhere other than this computer — each stays valid until it is used, and you can generate a new set at any time. To sign in with one, click “Didn’t receive a notification?” → “Choose Another Verification Method” → “Recovery Codes”.
The code is not accepted?
Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.
If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Do I need Salesforce Authenticator for Heroku?
- No. Salesforce Authenticator sends push notifications, but Heroku equally accepts a one-time password generator — any app that produces standard time-based codes. Heroku names Google Authenticator, Microsoft Authenticator and Authy; the Authenticator extension works the same way and reads the QR code straight off the Dashboard.
- How do I log in to the Heroku CLI with multi-factor authentication?
- Run heroku login: it opens the browser, where you sign in to the Dashboard and enter the code from the extension. The --interactive option, which asks for the password in the terminal, cannot be used with multi-factor authentication.
- What if I lose access to my authenticator?
- Sign in with a recovery code, then set the authenticator up again. In a Heroku Enterprise Account, an admin can send you a temporary verification code with “Send MFA Recovery Token” on the account’s Access tab. Otherwise contact Heroku Support, which may ask for extra information to make sure it is you.
- Why does Heroku say my code is wrong?
- Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If it still fails, remove the account from the extension, delete the one-time password generator under Manage Multi-Factor Authentication, and add it again.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free